CVE-2014-1948 - CERT CVE
ID CVE-2014-1948
Sažetak OpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARNING level logging is enabled, which allows local users to obtain sensitive information by reading the log.
Reference
CVSS
Base: 2.6
Impact: 4.9
Exploitability:1.9
Pristup
VektorSloženostAutentikacija
LOCAL HIGH NONE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL PARTIAL NONE
CVSS vektor AV:L/AC:H/Au:N/C:P/I:P/A:N
Zadnje važnije ažuriranje 08-03-2014 - 05:13
Objavljeno 14-02-2014 - 15:55