Back

LOW

openstack-nova: leak consoleauth tokens into log files

Published Feb 19, 2020

Description

An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.new_websocket_client in console/websocketproxy.py.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 19, 2020
Updated Aug 6, 2024
Reserved Feb 19, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Sep 4, 2015
GHSA-22JM-4HXW-35JF