Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-9543

Опубликовано: 19 фев. 2020
Источник: debian
EPSS Низкий

Описание

An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.new_websocket_client in console/websocketproxy.py.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
novafixed2:20.1.1-1package
novano-dsabusterpackage
novano-dsastretchpackage
novano-dsajessiepackage

Примечания

  • https://launchpad.net/bugs/1492140

  • https://review.opendev.org/220622

  • https://www.openwall.com/lists/oss-security/2020/02/19/2

EPSS

Процентиль: 34%
0.00132
Низкий

Связанные уязвимости

CVSS3: 3.3
ubuntu
больше 5 лет назад

An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.new_websocket_client in console/websocketproxy.py.

CVSS3: 3.3
redhat
почти 10 лет назад

An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.new_websocket_client in console/websocketproxy.py.

CVSS3: 3.3
nvd
больше 5 лет назад

An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.new_websocket_client in console/websocketproxy.py.

CVSS3: 3.3
github
около 3 лет назад

OpenStack Nova can leak consoleauth token into log files

EPSS

Процентиль: 34%
0.00132
Низкий