CVE-2014-7230
EPSS 0.12%Published: 10/8/2014Modified: 4/28/2026
Description
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.
Affected packages (3)
- Debian/cinderfrom 0, < 2014.1.3-4
- Debian/novafrom 0, < 2014.1.3-5
- Debian/openstack-trovefrom 0, < 2014.1.3-1