CVE-2015-9543 describes a vulnerability in OpenStack Nova, affecting versions before 18.2.4, 19.1.0, and 20.1.0, specifically impacting setups utilizing novncproxy. The flaw allows consoleauth tokens to be inadvertently leaked into log files, making them accessible to attackers with read privileges to those logs. This vulnerability carries a low severity CVSS score of 3.3, indicating that an attacker with local access to the system could potentially compromise the confidentiality of console access tokens. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.2.4CPE matchmatch criteria | cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:* | ||
>= 19.0.0, < 19.1.0CPE matchmatch criteria | cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:* | ||
>= 20.0.0, < 20.1.0CPE matchmatch criteria | cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.