CVE-2014-1948
openstack-glance: Glance Swift store backend password leak
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARNING level logging is enabled, which allows local users to obtain sensitive information by reading the log.
OpenStack Image Registry and Delivery Service (Glance) 2013.2 hasta 2013.2.1 y Icehouse anterior a icehouse-2 registra una URL que contiene la contraseña de Swift store backend cuando falla la autenticación y el registro a nivel de advertencia está habilitado, lo que permite a usuarios locales obtener información sensible mediante la lectura del registro.
OpenStack Image service provides discovery, registration, and delivery services for disk and server images. It provides the ability to copy or snapshot a server image, and immediately store it away. Stored images can be used as a template to get new servers up and running quickly and more consistently than installing a server operating system and individually configuring additional services. An information leak flaw was found in the way glance stored certain logging information. An attacker with access to the glance log files could use this flaw to obtain authentication credentials to the OpenStack Object Storage back end. Note that only setups using the swift back end were affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-02-12 CVE Reserved
- 2014-02-14 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-255: Credentials Management Errors
- CWE-532: Insertion of Sensitive Information into Log File
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://secunia.com/advisories/56419 | Third Party Advisory | |
http://www.openwall.com/lists/oss-security/2014/02/12/18 | Mailing List |
|
http://www.securityfocus.com/bid/65507 | Vdb Entry | |
https://bugs.launchpad.net/glance/+bug/1275062 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2014-0229.html | 2014-03-08 | |
https://access.redhat.com/security/cve/CVE-2014-1948 | 2014-03-04 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1064589 | 2014-03-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openstack Search vendor "Openstack" | Image Registry And Delivery Service \(glance\) Search vendor "Openstack" for product "Image Registry And Delivery Service \(glance\)" | 2013.2 Search vendor "Openstack" for product "Image Registry And Delivery Service \(glance\)" and version "2013.2" | - |
Affected
| ||||||
Openstack Search vendor "Openstack" | Image Registry And Delivery Service \(glance\) Search vendor "Openstack" for product "Image Registry And Delivery Service \(glance\)" | 2013.2.1 Search vendor "Openstack" for product "Image Registry And Delivery Service \(glance\)" and version "2013.2.1" | - |
Affected
|