CVE-2015-8749: Infoleak
Published Jan 15, 2016
·Updated
The volumeutils.parsevolumeinfo function in OpenStack Compute (Nova) before 2015.1.3 (kilo) and 12.0.x before 12.0.1 (liberty) includes the connectioninfo dictionary in the StorageError message when using the Xen backend, which might allow attackers to obtain sensitive password information by reading log files or other unspecified vectors.
Affected Software
3 affected componentsFixes available
pip/nova>=12.0.0<12.0.1
12.0.1
Openstack Nova>=12.0.0<12.0.1
Openstack Nova>=2015.1.0<2015.1.3
Remediation
Patch Available
Event History
Jan 15, 2016
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·01:58 AM
Frequently Asked Questions
1
What is the severity of CVE-2015-8749?
CVE-2015-8749 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2015-8749?
To remediate CVE-2015-8749, upgrade OpenStack Nova to version 12.0.1 or later.
3
Which versions of OpenStack Nova are affected by CVE-2015-8749?
CVE-2015-8749 affects OpenStack Nova versions before 2015.1.3 and 12.0.x before 12.0.1.
4
What type of vulnerability is CVE-2015-8749?
CVE-2015-8749 is an information disclosure vulnerability.
5
What might attackers gain access to through CVE-2015-8749?
Attackers might obtain sensitive password information due to the inclusion of connection_info in error messages.