VulnerabilityModified
CVE-2015-9543
It can leak consoleauth tokens into log files.
LOW 3.3EPSS 0.41%
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.new_websocket_client in console/websocketproxy.py.
- CVSS 3.1
- 3.3 LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.41% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- openstack/nova
- Source
- cve@mitre.org
References
- http://www.openwall.com/lists/oss-security/2020/02/19/2Mailing List, Patch, Third Party Advisory
- https://launchpad.net/bugs/1492140Issue Tracking, Third Party Advisory
- https://review.opendev.org/220622Third Party Advisory
- https://security.openstack.org/ossa/OSSA-2020-001.htmlPatch, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2020/02/19/2Mailing List, Patch, Third Party Advisory
- https://launchpad.net/bugs/1492140Issue Tracking, Third Party Advisory
- https://review.opendev.org/220622Third Party Advisory
- https://security.openstack.org/ossa/OSSA-2020-001.htmlPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.