Vulnerability Description
An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect sensitive data after discovering the IP address of the undercloud, possibly leading to compromising private information, including administrator access credentials.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Openstack Platform | 13.0 |
Related Weaknesses (CWE)
References
- https://access.redhat.com/errata/RHSA-2022:8897Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2022-3596MitigationVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2136596Issue TrackingVendor Advisory
- https://access.redhat.com/errata/RHSA-2022:8897Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2022-3596MitigationVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2136596Issue TrackingVendor Advisory
FAQ
What is CVE-2022-3596?
CVE-2022-3596 is a vulnerability with a CVSS score of 7.5 (HIGH). An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect sensitive data after discovering the IP address of the undercloud, possibly leadi...
How severe is CVE-2022-3596?
CVE-2022-3596 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-3596?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Openstack Platform.