7.4

CVE-2023-1625

Exploit

An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.

Data is provided by the National Vulnerability Database (NVD)
OpenstackHeat Version-
RedhatOpenstack Platform Version13.0
RedhatOpenstack Platform Version16.1
RedhatOpenstack Platform Version16.2
RedhatOpenstack Platform Version17.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.12% 0.316
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 3.1 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
secalert@redhat.com 7.4 3.1 3.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
CWE-202 Exposure of Sensitive Information Through Data Queries

When trying to keep information confidential, an attacker can often infer some of the information by using statistics.