Severity
3.3LOW
EPSS
0.1%
top 75.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 19
Latest updateFeb 13

Description

An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.new_websocket_client in console/websocketproxy.py.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages5 packages

NVDopenstack/nova19.0.019.1.0+2
PyPINova19.0.019.1.0+2
PyPInova19.0.019.1.0+2
Debiannova< 2:20.1.1-1+3
Ubuntunova< 2:17.0.13-0ubuntu5.3+2

Patches

🔴Vulnerability Details

5
OSV
nova vulnerabilities2023-02-13
GHSA
OpenStack Nova can leak consoleauth token into log files2022-05-24
OSV
OpenStack Nova can leak consoleauth token into log files2022-05-24
CVEList
CVE-2015-9543: An issue was discovered in OpenStack Nova before 182020-02-19
OSV
CVE-2015-9543: An issue was discovered in OpenStack Nova before 182020-02-19

📋Vendor Advisories

3
Ubuntu
Nova vulnerabilities2023-02-13
Red Hat
openstack-nova: leak consoleauth tokens into log files2015-09-04
Debian
CVE-2015-9543: nova - An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and...2015

💬Community

2
Bugzilla
CVE-2015-9543 openstack-nova: leak consoleauth tokens into log files2020-02-20
Bugzilla
CVE-2015-9543 openstack-nova: leak consoleauth tokens into log files [openstack-rdo]2020-02-20
CVE-2015-9543 (LOW CVSS 3.3) | An issue was discovered in OpenStac | cvebase.io