Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-14433


An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.


Published

2019-08-09T19:15:11.577

Last Modified

2024-11-21T04:26:44.467

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-209

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application openstack nova < 17.0.12 Yes
Application openstack nova < 18.2.2 Yes
Application openstack nova < 19.0.2 Yes
Operating System canonical ubuntu_linux 16.04 Yes
Operating System canonical ubuntu_linux 18.04 Yes
Operating System canonical ubuntu_linux 19.04 Yes
Application redhat openstack 10 Yes
Application redhat openstack 13 Yes
Application redhat openstack 14 Yes
Operating System debian debian_linux 10.0 Yes

References