CVE-2015-9543 Details
Description
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.new_websocket_client in console/websocketproxy.py.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://launchpad.net/bugs/1492140 | CVE | Issue TrackingThird Party Advisory |
| https://review.opendev.org/220622 | CVE | Third Party Advisory |
| https://security.openstack.org/ossa/OSSA-2020-001.html | CVE | PatchVendor Advisory |
| http://www.openwall.com/lists/oss-security/2020/02/19/2 | CVE | Mailing ListPatchThird Party Advisory |
| https://launchpad.net/bugs/1492140 | [email protected] | Issue TrackingThird Party Advisory |
| https://review.opendev.org/220622 | [email protected] | Third Party Advisory |
| https://security.openstack.org/ossa/OSSA-2020-001.html | [email protected] | PatchVendor Advisory |
| http://www.openwall.com/lists/oss-security/2020/02/19/2 | [email protected] | Mailing ListPatchThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openstack nova | < 18.2.4 >= 19.0.0, < 19.1.0 >= 20.0.0, < 20.1.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Feb 27, 2020 | Initial Analysis | [email protected] |
| Feb 19, 2020 | CVE Modified | [email protected] |
| Feb 19, 2020 | CVE Modified | [email protected] |