SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-8749

The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the connection_info dictionary in the StorageError message when using the Xen backend, which might allow…

MEDIUM 5.9EPSS 2.24%

Does this matter?

Lower severity and a low EPSS score (2.24%). Track it; it rarely justifies an emergency change on its own.

Description

The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the connection_info dictionary in the StorageError message when using the Xen backend, which might allow attackers to obtain sensitive password information by reading log files or other unspecified vectors.

CVSS 3.0
5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
2.24% probability · 82th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
openstack/nova
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.