CVE-2017-7214: Critical severity Openstack Nova vulnerability
An issue was discovered in exceptionwrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notification exception contexts appearing in ERROR level logs may include sensitive information such as account passwords and authorization tokens.
Other sources
An issue was discovered in exceptionwrapper.py in OpenStack Nova. Legacy notification exception contexts appearing in ERROR level logs may include sensitive information such as account passwords and authorization tokens.
Upstream bug:
https://bugs.launchpad.net/nova/+bug/1673569
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/novato a version that resolves this vulnerability.Fixed in 15.0.2 - Upgrade
Upgrade
pip/novato a version that resolves this vulnerability.Fixed in 14.0.5 - Upgrade
Upgrade
pip/novato a version that resolves this vulnerability.Fixed in 13.1.4
Event History
Frequently Asked Questions
What are the affected versions for CVE-2017-7214?
CVE-2017-7214 affects OpenStack Nova versions 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1.
What is the impact of CVE-2017-7214?
CVE-2017-7214 exposes sensitive information such as account passwords and authorization tokens in ERROR level logs of OpenStack Nova.
How do I fix CVE-2017-7214?
To resolve CVE-2017-7214, you should upgrade to Nova version 15.0.2, 14.0.5, or 13.1.4.
What type of vulnerability is CVE-2017-7214?
CVE-2017-7214 is classified as a logging vulnerability in OpenStack Nova.
Is CVE-2017-7214 a critical vulnerability?
CVE-2017-7214 has a high severity rating due to the risk of exposing sensitive information.