Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-1625

Опубликовано: 24 сент. 2023
Источник: debian
EPSS Низкий

Описание

An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
heatfixed1:20.0.0~rc1-1experimentalpackage
heatfixed1:19.0.0-2package
heatno-dsabullseyepackage
heatno-dsabusterpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2181621

  • https://review.opendev.org/c/openstack/heat/+/868166

  • https://github.com/openstack/heat/commit/1305a3152f75c6e62ec5094ea2bfc38f165204cf (20.0.0.0rc1)

  • When fixing the issue make sure to apply the complete follow up fix to not open up CVE-2024-7319

EPSS

Процентиль: 44%
0.00212
Низкий

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 2 лет назад

An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.

CVSS3: 7.4
redhat
около 3 лет назад

An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.

CVSS3: 7.4
nvd
больше 2 лет назад

An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.

CVSS3: 7.4
github
больше 2 лет назад

OpenStack Heat information leak vulnerability

EPSS

Процентиль: 44%
0.00212
Низкий