CVE-2014-7231 describes a vulnerability in the OpenStack Oslo utility library, Cinder, Nova, and Trove, affecting versions before 2013.2.4 and 2014.1 before 2014.1.3. The strutils.mask_password function failed to properly mask passwords when logging commands, allowing local users to retrieve sensitive credentials by reading log files. This vulnerability has a low severity CVSS score of 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N), indicating local access is required with low attack complexity, resulting in a potential compromise of confidentiality. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2013.2, < 2013.2.4CPE matchmatch criteria | cpe:2.3:a:openstack:cinder:*:*:*:*:*:*:*:* | ||
>= 2014.1, < 2014.1.3CPE matchmatch criteria | cpe:2.3:a:openstack:cinder:*:*:*:*:*:*:*:* | ||
>= 2013.2, < 2013.2.4CPE matchmatch criteria | cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:* | ||
>= 2014.1, < 2014.1.3CPE matchmatch criteria | cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:* | ||
>= 2013.2, < 2013.2.4CPE matchmatch criteria | cpe:2.3:a:openstack:trove:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.