| Vulnerability Name: | CVE-2015-8749 (CCN-109585) | ||||||||||||||||||||
| Assigned: | 2016-01-11 | ||||||||||||||||||||
| Published: | 2016-01-11 | ||||||||||||||||||||
| Updated: | 2018-11-16 | ||||||||||||||||||||
| Summary: | The volume_utils._parse_volume_info function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the connection_info dictionary in the StorageError message when using the Xen backend, which might allow attackers to obtain sensitive password information by reading log files or other unspecified vectors. | ||||||||||||||||||||
| CVSS v3 Severity: | 5.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N) 5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||||
| Vulnerability Type: | CWE-200 | ||||||||||||||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2015-8749 Source: CCN Type: oss-sec Mailing List, Thu, 7 Jan 2016 15:40:53 -0500 (EST) Re: CVE request for vulnerability in OpenStack Nova Source: CCN Type: IBM Security Bulletin T1023865 (SmartCloud Entry) OpenStack vulnerabilities affect IBM SmartCloud Entry(CVE-2015-7548, CVE-2015-8749 CVE-2015-1850) Source: CCN Type: IBM Security Bulletin T1024106 (Cloud Manager with Openstack) OpenStack vulnerabilities affect IBM Cloud Manager with Openstack (CVE-2015-7548, CVE-2015-8749 CVE-2015-1850) Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20160107 CVE request for vulnerability in OpenStack Nova Source: MLIST Type: Mailing List, Third Party Advisory [oss-security] 20160107 Re: CVE request for vulnerability in OpenStack Nova Source: CCN Type: oss-sec Mailing List, Tue, 12 Jan 2016 10:07:25 -0800 [OSSA 2016-002] Xen connection password leak in logs via StorageError (CVE-2015-8749) Source: BID Type: Third Party Advisory, VDB Entry 80189 Source: CCN Type: BID-80189 OpenStack Nova CVE-2015-8749 Information Disclosure Vulnerability Source: CCN Type: OSSA 2016-002 xenapi: volume_utils._parse_volume_info can leak connection password via StorageError (CVE-2015-8749) Source: CONFIRM Type: Third Party Advisory https://bugs.launchpad.net/nova/+bug/1516765 Source: CCN Type: Red Hat Bugzilla Bug 1296837 (CVE-2015-8749) CVE-2015-8749 openstack-nova: Xen connection password leak in logs via StorageError Source: XF Type: UNKNOWN openstack-nova-cve20158749-info-disc(109585) Source: CONFIRM Type: Patch, Vendor Advisory https://security.openstack.org/ossa/OSSA-2016-002.html Source: CCN Type: WhiteSource Vulnerability Database CVE-2015-8749 | ||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
| BACK | |||||||||||||||||||||