OpenStack Oslo utility sensitive information exposure via log files
Low severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated May 14, 2024
Description
Published by the National Vulnerability Database
Oct 8, 2014
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
May 14, 2024
Last updated
May 14, 2024
The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.
References