PT-2022-5772 · Openstack · Openstack Platform

Nick Tait

·

Published

2022-12-05

·

Updated

2024-05-03

·

CVE-2022-3596

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenStack Platform (affected versions not specified)
Description The issue is related to an information leak found in OpenStack's undercloud, which allows unauthenticated, remote attackers to inspect sensitive data after discovering the IP address of the undercloud. This could lead to compromising private information, including administrator access credentials.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2022-07172
CVE-2022-3596
RHSA-2022:8897

Affected Products

Openstack Platform