CVE-2014-7230
EPSS 0.12%
Description
The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.
How to fix CVE-2014-7230
To remediate CVE-2014-7230, upgrade the affected package to a fixed version below.
- Debian/cinder—upgrade to 2014.1.3-4 or later
- Debian/nova—upgrade to 2014.1.3-5 or later
- Debian/openstack-trove—upgrade to 2014.1.3-1 or later
Is CVE-2014-7230 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 2014.1.3-4
- from 0, < 2014.1.3-5
- from 0, < 2014.1.3-1