CVE-2023-1625
An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.4
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
- EPSS probability
- 0.21%
- CWE
- CWE-202
- Published
- 2023-09-24
- Last modified
- 2026-03-13
Weakness type
Related vulnerabilities
- CVE-2021-32743 — Passwords used to access external services inadvertently exposed through API
- CVE-2025-25205 — Remote Authentication-Bypass can lead to server crash or limited information disclosure due to faulty pattern matching
- CVE-2026-33530 — InvenTree Vulnerable to ORM Filter Injection
- CVE-2025-69200 — phpMyFAQ has unauthenticated config backup download via /api/setup/backup
- CVE-2025-36575 — Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Through Data Queries
- CVE-2025-29981 — Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Exposure of Sensitive Information Through Data Querie
- CVE-2026-16520 — Improper input validation and Exposure of sensitive information through data queries vulnerability in Genians Genian NAC
- CVE-2024-2088 — NextScripts: Social Networks Auto-Poster <= 4.4.3 - Authenticated(Subscriber+) Sensitive Information Exposure