GHSA-c36r-g737-9qp8

Suggest an improvement
Source
https://github.com/advisories/GHSA-c36r-g737-9qp8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-c36r-g737-9qp8/GHSA-c36r-g737-9qp8.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-c36r-g737-9qp8
Aliases
Published
2022-05-14T01:58:45Z
Modified
2024-05-14T21:41:49.165255Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
OpenStack Nova Potential Xen connection password leak via StorageError
Details

The volumeutils.parsevolumeinfo function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the connection_info dictionary in the StorageError message when using the Xen backend, which might allow attackers to obtain sensitive password information by reading log files or other unspecified vectors.

Database specific
{
    "nvd_published_at": "2016-01-15T19:59:00Z",
    "cwe_ids": [
        "CWE-200"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-05-14T21:13:52Z"
}
References

Affected packages

PyPI / nova

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
12.0.0
Fixed
12.0.1