An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.
2019-08-09T19:15:11.577
2024-11-21T04:26:44.467
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | openstack | nova | < 17.0.12 | Yes |
| Application | openstack | nova | < 18.2.2 | Yes |
| Application | openstack | nova | < 19.0.2 | Yes |
| Operating System | canonical | ubuntu_linux | 16.04 | Yes |
| Operating System | canonical | ubuntu_linux | 18.04 | Yes |
| Operating System | canonical | ubuntu_linux | 19.04 | Yes |
| Application | redhat | openstack | 10 | Yes |
| Application | redhat | openstack | 13 | Yes |
| Application | redhat | openstack | 14 | Yes |
| Operating System | debian | debian_linux | 10.0 | Yes |