CVE-2014-7230
OpenStack <2013.2.4 & <2014.1.3 - Info Disclosure
Title source: llmDescription
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.
References (6)
Scores
EPSS
0.0012
EPSS Percentile
31.3%
Classification
CWE
CWE-200
Status
draft
Affected Products (5)
openstack/cinder
< 2013.2.4
openstack/nova
< 2013.2.4
openstack/trove
< 2013.2.4
redhat/openstack
canonical/ubuntu_linux
Timeline
Published
Oct 08, 2014
Tracked Since
Feb 18, 2026