Information leak in api

CVE Details

Basic Information

Title Information leak in api
Type cve
Published 2023-09-24T00:08:12.738Z
Modified 2024-09-24T14:59:25.505Z

Product Information

Vendor n/a
Product openstack-heat

CVSS Information

Base Score 7.4 (HIGH)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

Additional Information

CWE List CWE-202
Source redhat

Description

An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the ‘stack show’ command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.