cinder: information disclosure
| Package(s): | cinder | CVE #(s): | CVE-2014-7230 | ||||||||||||
| Created: | November 12, 2014 | Updated: | December 3, 2014 | ||||||||||||
| Description: | From the CVE entry:
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log. | ||||||||||||||
| Alerts: |
| ||||||||||||||
