CVE-2015-8749

Severity
5.9MEDIUM
EPSS
0.9%
top 23.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 15
Latest updateMay 14

Description

The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the connection_info dictionary in the StorageError message when using the Xen backend, which might allow attackers to obtain sensitive password information by reading log files or other unspecified vectors.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages3 packages

NVDopenstack/nova12.0.012.0.1+1
PyPInova12.0.012.0.1
Debiannova< 2:13.0.0~rc3-1+3

Patches

🔴Vulnerability Details

4
OSV
OpenStack Nova Potential Xen connection password leak via StorageError2022-05-14
GHSA
OpenStack Nova Potential Xen connection password leak via StorageError2022-05-14
OSV
CVE-2015-8749: The volume_utils2016-01-15
CVEList
CVE-2015-8749: The volume_utils2016-01-15

📋Vendor Advisories

3
Ubuntu
OpenStack Nova vulnerabilities2017-10-11
Red Hat
openstack-nova: Xen connection password leak in logs via StorageError2016-01-07
Debian
CVE-2015-8749: nova - The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before ...2015

💬Community

2
Bugzilla
CVE-2015-8749 openstack-nova: Xen connection password leak in logs via StorageError2016-01-08
Bugzilla
CVE-2015-8749 openstack-nova: Xen connection password leak in logs via StorageError [fedora-all]2016-01-08
CVE-2015-8749 (MEDIUM CVSS 5.9) | The volume_utils._parse_volume_info | cvebase.io