CVE-2015-9543

Description

An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the services logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.new_websocket_client in console/websocketproxy.py.

Risk Information

Base Score
3.3
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.083

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2015-9543 are fixed in Python-nova 18.2.4Windows
Vulnerabilities CVE-2015-9543 are fixed in Python-nova 19.1.0Windows
Vulnerabilities CVE-2015-9543 are fixed in Python-nova 20.1.0Windows
OpenStack Compute cloud infrastructure (USN-5866-1) nova-common_21.2.4-0ubuntu2.2_all.debLinux
OpenStack Compute cloud infrastructure (USN-5866-1) nova-common_17.0.13-0ubuntu5.3_all.debLinux
OpenStack Compute cloud infrastructure (USN-5866-1) python-nova_17.0.13-0ubuntu5.3_all.debLinux
OpenStack Compute cloud infrastructure (USN-5866-1) python3-nova_21.2.4-0ubuntu2.2_all.debLinux
OpenStack Compute cloud infrastructure (USN-5866-1) nova-common_21.2.4-0ubuntu2.2_all.debLinux
Vulnerabilities CVE-2015-9543 are fixed in Python-nova for linux 18.2.4Linux
Vulnerabilities CVE-2015-9543 are fixed in Python-nova for linux 19.1.0Linux
Vulnerabilities CVE-2015-9543 are fixed in Python-nova for linux 20.1.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234