CVE Vulnerabilities

CVE-2023-1625

Exposure of Sensitive Information Through Data Queries

Published: Sep 24, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
7.4 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Ubuntu
MEDIUM

An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the stack show command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.

Weakness

When trying to keep information confidential, an attacker can often infer some of the information by using statistics.

Affected Software

Name Vendor Start Version End Version
Heat Openstack - (including) - (including)
Heat Ubuntu bionic *
Heat Ubuntu focal *
Heat Ubuntu jammy *
Heat Ubuntu kinetic *
Heat Ubuntu trusty *
Heat Ubuntu xenial *

Potential Mitigations

References