CVE-2014-7231: Openstack Cinder

Low severity, CVSS 2.1. EPSS: 0.5% chance of exploitation in the next 30 days.

The strutils.mask_password function in the OpenStack Oslo utility library, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 does not properly mask passwords when logging commands, which allows local users to obtain passwords by reading the log.

Affected products

  • Openstack Cinder: from 2013.2, before 2013.2.4 (fixed in 2013.2.4); from 2014.1, before 2014.1.3 (fixed in 2014.1.3)
  • Openstack Nova: from 2013.2, before 2013.2.4 (fixed in 2013.2.4); from 2014.1, before 2014.1.3 (fixed in 2014.1.3)
  • Openstack Trove: from 2013.2, before 2013.2.4 (fixed in 2013.2.4); from 2014.1, before 2014.1.3 (fixed in 2014.1.3)
  • Red Hat Openstack: version 5.0 only

Published 2014-10-08. Last modified 2026-06-17.