Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-22jm-4hxw-35jf

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 3.3

Описание

OpenStack Nova can leak consoleauth token into log files

An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.new_websocket_client in console/websocketproxy.py.

Пакеты

Наименование

Nova

pip
Затронутые версииВерсия исправления

< 18.2.4

18.2.4

Наименование

Nova

pip
Затронутые версииВерсия исправления

>= 19.0.0, < 19.1.0

19.1.0

Наименование

Nova

pip
Затронутые версииВерсия исправления

>= 20.0.0, < 20.1.0

20.1.0

EPSS

Процентиль: 34%
0.00132
Низкий

3.3 Low

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 3.3
ubuntu
больше 5 лет назад

An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.new_websocket_client in console/websocketproxy.py.

CVSS3: 3.3
redhat
почти 10 лет назад

An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.new_websocket_client in console/websocketproxy.py.

CVSS3: 3.3
nvd
больше 5 лет назад

An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.new_websocket_client in console/websocketproxy.py.

CVSS3: 3.3
debian
больше 5 лет назад

An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 1 ...

EPSS

Процентиль: 34%
0.00132
Низкий

3.3 Low

CVSS3

Дефекты

CWE-200