|
|
Log in / Subscribe / Register

cinder: information disclosure

Package(s):cinder CVE #(s):CVE-2014-7230
Created:November 12, 2014 Updated:December 3, 2014
Description: From the CVE entry:

The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.

Alerts:
Red Hat RHSA-2014:1939-01 openstack-trove 2014-12-02
Ubuntu USN-2407-1 nova 2014-11-11
Ubuntu USN-2405-1 cinder 2014-11-11

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds