CVE-2015-9543
Summary
| CVE | CVE-2015-9543 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-19 03:15:00 UTC |
| Updated | 2020-02-27 19:17:00 UTC |
| Description | An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.new_websocket_client in console/websocketproxy.py. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| OpenStack Docs: OSSA-2020-001: Nova can leak consoleauth token into log files | CONFIRM | security.openstack.org | Patch, Vendor Advisory |
| oss-security - [OSSA-2020-001] Nova can leak consoleauth token into log files (CVE-2015-9543) | MLIST | www.openwall.com | Mailing List, Patch, Third Party Advisory |
| Gerrit Code Review | MISC | review.opendev.org | Third Party Advisory |
| Bug #1492140 “[OSSA-2020-001] Nova can leak consoleauth token in...” : Bugs : OpenStack Compute (nova) | MISC | launchpad.net | Issue Tracking, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 199170 Ubuntu Security Notification for Nova Vulnerabilities (USN-5866-1)