CVE-2023-1625

Description

An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.

Statement

While this flaw leaks a password which could reduce confidentiality, integrity, and availability, the impact to this triad is rated low. This is because OpenStack can not be more broadly compromised for two reasons: a) The host has separate authorization authority from the guest virtual machine b) The guest virtual machines that are configured by different stack configurations cannot be compromised

Therefore the overall impact of the flaw is rated Moderate.

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score7.457.4
Attack VectorNetworkNetworkNetwork
Attack ComplexityLowLowLow
Privileges RequiredLowLowLow
User InteractionNoneNoneNone
ScopeChangedChangedChanged
ConfidentialityLowLowLow
Integrity ImpactLowNoneLow
Availability ImpactLowNoneLow

Vector

Red Hat: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

NVD: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

cve.org: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

Red Hat CVSS v3 Score Explanation

Attack Complexity is rated Low: Specialized conditions or advanced knowledge are not required.

Privileges Required is rated Low: In deployments which utilize lax RBAC permissions, administrators could grant all general users the ability to create a new stack.

Scope is rated Changed: The vulnerable component is the host OpenStack infrastructure and the impacted components are guest virtual machines.

Understanding the Weakness (CWE)

Confidentiality

Technical Impact: Read Files or Directories; Read Application Data

Sensitive information may possibly be leaked through data queries accidentally.

Acknowledgements

Red Hat would like to thank Chengen Du (Canonical) for reporting this issue.

Frequently Asked Questions

Want to get errata notifications? Sign up here.