CVE-2014-1948

NameCVE-2014-1948
DescriptionOpenStack Image Registry and Delivery Service (Glance) 2013.2 through 2013.2.1 and Icehouse before icehouse-2 logs a URL containing the Swift store backend password when authentication fails and WARNING level logging is enabled, which allows local users to obtain sensitive information by reading the log.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs738924

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
glance (PTS)jessie2014.1.3-12+deb8u1fixed
stretch2:13.0.0-4fixed
buster (security), buster, buster (lts)2:17.0.0-5+deb10u1fixed
bullseye2:21.0.0-2+deb11u1fixed
bullseye (security)2:21.1.0-1+deb11u2fixed
bookworm (security), bookworm2:25.1.0-2+deb12u1fixed
sid, trixie2:29.0.0-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
glancesourcewheezy(not affected)
glancesource(unstable)2013.2.2-1738924

Notes

[wheezy] - glance <not-affected> (Only affects Havana)
https://launchpad.net/bugs/1275062

Search for package or bug name: Reporting problems