CVE Vulnerabilities

CVE-2014-1948

Published: Feb 14, 2014 | Modified: Mar 08, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.6 LOW
AV:L/AC:H/Au:N/C:P/I:P/A:N
RedHat/V2
3.3 MODERATE
AV:L/AC:M/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM

OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARNING level logging is enabled, which allows local users to obtain sensitive information by reading the log.

Affected Software

Name Vendor Start Version End Version
Image_registry_and_delivery_service_(glance) Openstack 2013.2 (including) 2013.2 (including)
Image_registry_and_delivery_service_(glance) Openstack 2013.2.1 (including) 2013.2.1 (including)
OpenStack 4 for RHEL 6 RedHat openstack-glance-0:2013.2.2-2.el6ost *
Glance Ubuntu upstream *

References