CVE-2015-9543
published 2020-02-19CVE-2015-9543: An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker…
PriorityP411low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EPSS
0.41%
33.1th percentile
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.new_websocket_client in console/websocketproxy.py.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2:20.1.1-1 (bookworm) | nova 2:20.1.1-1 (bookworm) |
| openstack | nova | < 18.2.4 | 18.2.4 |
| openstack | nova | >= 0 < 2:20.1.1-1 | 2:20.1.1-1 |
| openstack | nova | >= 0 < 2:20.1.1-1 | 2:20.1.1-1 |
| openstack | nova | >= 0 < 2:20.1.1-1 | 2:20.1.1-1 |
| openstack | nova | >= 0 < 2:20.1.1-1 | 2:20.1.1-1 |
| openstack | nova | >= 0 < 18.2.4 | 18.2.4 |
| openstack | nova | >= 0 < 2:17.0.13-0ubuntu5.3 | 2:17.0.13-0ubuntu5.3 |
| openstack | nova | >= 0 < 2:21.2.4-0ubuntu2.2 | 2:21.2.4-0ubuntu2.2 |
| openstack | nova | >= 0 < 2:13.1.4-0ubuntu4.5+esm1 | 2:13.1.4-0ubuntu4.5+esm1 |
| openstack | nova | >= 19.0.0 < 19.1.0 | 19.1.0 |
| openstack | nova | >= 19.0.0 < 19.1.0 | 19.1.0 |
| openstack | nova | >= 20.0.0 < 20.1.0 | 20.1.0 |
| openstack | nova | >= 20.0.0 < 20.1.0 | 20.1.0 |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
nova vulnerabilities
osv·2023-02-13·CVSS 3.3
CVE-2015-9543 [LOW] nova vulnerabilities
nova vulnerabilities
It was discovered that Nova did not properly manage data logged into the
log file. An attacker with read access to the service's logs could exploit
this issue and may obtain sensitive information. This issue only affected
Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2015-9543)
It was discovered that Nova did not properly handle attaching and
reattaching the encrypted volume. An attacker could possibly use this issue
to perform a denial of service attack. This issue only affected Ubuntu
16.04 ESM. (CVE-2017-18191)
It was discovered that Nova did not properly handle the updation of domain
XML after live migration. An attacker could possibly use this issue to
corrupt the volume or perform a denial of service attack. This issue only
affected Ubuntu 18.04 LTS. (CVE-2020-1
GHSA
OpenStack Nova can leak consoleauth token into log files
ghsa·2022-05-24
CVE-2015-9543 [LOW] CWE-200 OpenStack Nova can leak consoleauth token into log files
OpenStack Nova can leak consoleauth token into log files
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to `NovaProxyRequestHandlerBase.new_websocket_client` in `console/websocketproxy.py`.
OSV
OpenStack Nova can leak consoleauth token into log files
osv·2022-05-24
CVE-2015-9543 [LOW] OpenStack Nova can leak consoleauth token into log files
OpenStack Nova can leak consoleauth token into log files
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to `NovaProxyRequestHandlerBase.new_websocket_client` in `console/websocketproxy.py`.
OSV
CVE-2015-9543: An issue was discovered in OpenStack Nova before 18
osv·2020-02-19·CVSS 3.3
CVE-2015-9543 [LOW] CVE-2015-9543: An issue was discovered in OpenStack Nova before 18
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.new_websocket_client in console/websocketproxy.py.
Ubuntu
Nova vulnerabilities
vendor_ubuntu·2023-02-13·CVSS 3.3
CVE-2021-3654 [LOW] Nova vulnerabilities
Title: Nova vulnerabilities
Summary: Several security issues were fixed in Nova.
It was discovered that Nova did not properly manage data logged into the
log file. An attacker with read access to the service's logs could exploit
this issue and may obtain sensitive information. This issue only affected
Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2015-9543)
It was discovered that Nova did not properly handle attaching and
reattaching the encrypted volume. An attacker could possibly use this issue
to perform a denial of service attack. This issue only affected Ubuntu
16.04 ESM. (CVE-2017-18191)
It was discovered that Nova did not properly handle the updation of domain
XML after live migration. An attacker could possibly use this issue to
corrupt the volume or perform a denial of service a
Red Hat
openstack-nova: leak consoleauth tokens into log files
vendor_redhat·2015-09-04·CVSS 3.3
CVE-2015-9543 [LOW] CWE-532 openstack-nova: leak consoleauth tokens into log files
openstack-nova: leak consoleauth tokens into log files
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.new_websocket_client in console/websocketproxy.py.
A flaw was found in OpenStack Nova, where it leaks access tokens into log files. An attacker with access to the log files could use this information to gain additional access into an OpenStack deployment.
Package: openstack-nova (Red Hat OpenStack Platform 10 (Newton)) - Out of support scope
Package: openstack-nova (Red Hat OpenStack Platform 13 (Queen
Debian
CVE-2015-9543: nova - An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and...
vendor_debian·2015·CVSS 3.3
CVE-2015-9543 [LOW] CVE-2015-9543: nova - An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and...
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.new_websocket_client in console/websocketproxy.py.
Scope: local
bookworm: resolved (fixed in 2:20.1.1-1)
bullseye: resolved (fixed in 2:20.1.1-1)
forky: resolved (fixed in 2:20.1.1-1)
sid: resolved (fixed in 2:20.1.1-1)
trixie: resolved (fixed in 2:20.1.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-9543 openstack-nova: leak consoleauth tokens into log files
bugzilla·2020-02-20·CVSS 3.3
CVE-2015-9543 [LOW] CVE-2015-9543 openstack-nova: leak consoleauth tokens into log files
CVE-2015-9543 openstack-nova: leak consoleauth tokens into log files
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.new_websocket_client in console/websocketproxy.py.
Reference:
https://security.openstack.org/ossa/OSSA-2020-001.html
Discussion:
Created openstack-nova tracking bugs for this issue:
Affects: openstack-rdo [bug 1805389]
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2015-9543
Bugzilla
CVE-2015-9543 openstack-nova: leak consoleauth tokens into log files [openstack-rdo]
bugzilla·2020-02-20·CVSS 3.3
CVE-2015-9543 [LOW] CVE-2015-9543 openstack-nova: leak consoleauth tokens into log files [openstack-rdo]
CVE-2015-9543 openstack-nova: leak consoleauth tokens into log files [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
This product has been discont
http://www.openwall.com/lists/oss-security/2020/02/19/2https://launchpad.net/bugs/1492140https://review.opendev.org/220622https://security.openstack.org/ossa/OSSA-2020-001.htmlhttp://www.openwall.com/lists/oss-security/2020/02/19/2https://launchpad.net/bugs/1492140https://review.opendev.org/220622https://security.openstack.org/ossa/OSSA-2020-001.html
2020-02-19
Published