CVE-2014-1948: Openstack Image Registry And Delivery Service (glance)

Low severity, CVSS 2.6. EPSS: 0.3% chance of exploitation in the next 30 days.

OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARNING level logging is enabled, which allows local users to obtain sensitive information by reading the log.

Affected products

  • Openstack Image Registry And Delivery Service (glance): version 2013.2 only; version 2013.2.1 only

Published 2014-02-14. Last modified 2026-06-17.