Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to NovaProxyRequestHandlerBase.new_websocket_client in console/websocketproxy.py.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
OpenStack Nova 信息泄露漏洞
Vulnerability Description
OpenStack是美国国家航空航天局(National Aeronautics and Space Administration)和美国Rackspace公司合作研发的一个云平台管理项目。OpenStack Nova是其中的一个云计算结构控制器。 OpenStack Nova 18.2.4之前版本、19.1.0之前的19.x版本和20.1.0之前的20.x版本中存在安全漏洞,该漏洞源于程序将consoleauth令牌放在日志文件中。攻击者可利用该漏洞获取用控制台访问令牌。
CVSS Information
N/A
Vulnerability Type
N/A