Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-1625

Опубликовано: 27 янв. 2023
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.

Отчет

While this flaw leaks a password which could reduce confidentiality, integrity, and availability, the impact to this triad is rated low. This is because OpenStack can not be more broadly compromised for two reasons: a) The host has separate authorization authority from the guest virtual machine b) The guest virtual machines that are configured by different stack configurations cannot be compromised Therefore the overall impact of the flaw is rated Moderate.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 13 (Queens)openstack-heatOut of support scope
Red Hat OpenStack Platform 16.1openstack-heatWill not fix
Red Hat OpenStack Platform 16.2openstack-heatWill not fix
Red Hat OpenStack Platform 17.0openstack-heatFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-202
https://bugzilla.redhat.com/show_bug.cgi?id=2181621openstack-heat: information leak in API

EPSS

Процентиль: 44%
0.00212
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 2 лет назад

An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.

CVSS3: 7.4
nvd
больше 2 лет назад

An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.

CVSS3: 7.4
debian
больше 2 лет назад

An information leak was discovered in OpenStack heat. This issue could ...

CVSS3: 7.4
github
больше 2 лет назад

OpenStack Heat information leak vulnerability

EPSS

Процентиль: 44%
0.00212
Низкий

7.4 High

CVSS3