The processutils.execute function in OpenStack oslo-incubator, Cinder, Nova, and Trove before 2013.2.4 and 2014.1 before 2014.1.3 allows local users to obtain passwords from commands that cause a ProcessExecutionError by reading the log.
| Software | From | Fixed in |
|---|---|---|
| openstack / nova | 2014.1 | 2014.1.3 |
| openstack / cinder | 2013.2 | 2013.2.4 |
| openstack / nova | 2013.2 | 2013.2.4 |
| openstack / trove | 2013.2 | 2013.2.4 |
| openstack / cinder | 2014.1 | 2014.1.3 |
| openstack / trove | 2014.1 | 2014.1.3 |
| redhat / openstack | 5.0 | 5.0.x |
| canonical / ubuntu_linux | 14.04 | 14.04.x |