CVE-2023-1625
Title: Redhat Openstack Platform Improper Input Validation
Improper Input Validation
Proof Of Concept
No public PoC currently indexed for CVE-2023-1625.
CWE Category
CWE-202
Published Date
Sep 24, 2023
Modified Date
Nov 21, 2024
Exploit Status
Not Found
Score
7.4
CVSS v3.1
Exploit Probability (EPSS)
0.71%
Vulnerability Summary
CVE-2023-1625: An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.
Impacted Vendors
Reference Links
https://access.redhat.com/security/cve/CVE-2023-1625
https://bugzilla.redhat.com/show_bug.cgi?id=2181621
https://github.com/openstack/heat/commit/a49526c278e52823080c7f3fcb72785b93fd4dcb
https://launchpad.net/bugs/1999665
https://access.redhat.com/security/cve/CVE-2023-1625
https://bugzilla.redhat.com/show_bug.cgi?id=2181621
https://github.com/openstack/heat/commit/a49526c278e52823080c7f3fcb72785b93fd4dcb
https://launchpad.net/bugs/1999665
CVSS v3.1
Source Entity
[email protected]
Severity
HIGH
7.4
Attack Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
CHANGED
RAW VECTOR
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
CVSS v3.1
Source Entity
[email protected]
Severity
MEDIUM
5.0
Attack Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
Confidentiality
N/A
Integrity
N/A
Availability
N/A
Scope
CHANGED
RAW VECTOR
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2023-1625 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
NETWORK
Complexity
LOW
Privileges
N/A
Interaction
NONE
CVSS Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Affected Stack
No specific products linked.