CVE-2015-8749

MEDIUM5.9EPSS 0.94%

OpenStack Nova Potential Xen connection password leak via StorageError

發布日:2022/5/14修改日:2026/4/28
也稱為:DEBIAN-CVE-2015-8749

描述

The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the connection_info dictionary in the StorageError message when using the Xen backend, which might allow attackers to obtain sensitive password information by reading log files or other unspecified vectors.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.9CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

參考連結(12)