[OSSA-2020-001] Nova can leak consoleauth token into log files (CVE-2015-9543)
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Compute (nova) |
Fix Released
|
Low
|
Balazs Gibizer | ||
Pike |
Fix Released
|
Low
|
Elod Illes | ||
Queens |
Fix Released
|
Low
|
Balazs Gibizer | ||
Rocky |
Fix Committed
|
Low
|
Balazs Gibizer | ||
Stein |
Fix Released
|
Low
|
Balazs Gibizer | ||
Train |
Fix Released
|
Low
|
Balazs Gibizer | ||
OpenStack Security Advisory |
Fix Released
|
Low
|
Jeremy Stanley | ||
oslo.utils |
Fix Released
|
Low
|
Paul Carlton |
Bug Description
when instance console is accessed auth token is displayed nova-consoleaut
nova-consoleaut
nova-consoleaut
and
nova-novncproxy
This token has a short lifetime but the exposure still represents a potential security weakness, especially as the log record in question are INFO level and thus available via centralized logging. A user with real time access to these records could mount a denial of service attack by accessing the instance console and performing a ctl alt del to reboot it
Alternatively data privacy could be compromised if the attacker were able to obtain user credentials
CVE References
information type: | Private Security → Public |
Changed in oslo.utils: | |
status: | New → In Progress |
assignee: | nobody → Paul Carlton (paul-carlton2) |
importance: | Undecided → Low |
Changed in nova: | |
importance: | Undecided → Low |
Changed in ossa: | |
status: | Confirmed → Triaged |
tags: | added: console |
Changed in nova: | |
assignee: | Paul Carlton (paul-carlton2) → Tony Breeds (o-tony) |
Changed in nova: | |
assignee: | Tony Breeds (o-tony) → Paul Carlton (paul-carlton2) |
Changed in oslo.utils: | |
status: | In Progress → Fix Committed |
Changed in nova: | |
assignee: | Paul Carlton (paul-carlton2) → Andrea Rosa (andrea-rosa-m) |
Changed in nova: | |
assignee: | Andrea Rosa (andrea-rosa-m) → Paul Carlton (paul-carlton2) |
Changed in oslo.utils: | |
status: | Fix Committed → Fix Released |
Changed in nova: | |
assignee: | Paul Carlton (paul-carlton2) → Tristan Cacqueray (tristan-cacqueray) |
Changed in nova: | |
assignee: | Tristan Cacqueray (tristan-cacqueray) → Balazs Gibizer (balazs-gibizer) |
Changed in ossa: | |
assignee: | Tristan Cacqueray (tristan-cacqueray) → Jeremy Stanley (fungi) |
importance: | Undecided → Low |
summary: |
- Nova can leak consoleauth token into log files (CVE-2015-9543) + [OSSA-2020-001] Nova can leak consoleauth token into log files + (CVE-2015-9543) |
Since this report concerns a possible security risk, an incomplete security advisory task has been added while the core security reviewers for the affected project or projects confirm the bug and discuss the scope of any vulnerability along with potential solutions.
I've switched this report from public to public security since it seems to describe a potential vulnerability.