First published: Thu Aug 01 2019(Updated: )
A vulnerability was found in Nova Compute resource fault handling. If an API request from an authenticateduser ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response and could include sensitive configuration or other data.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Nova | <17.0.12 | |
OpenStack Nova | >=18.0.0<18.2.2 | |
OpenStack Nova | >=19.0.0<19.0.2 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =19.04 | |
Redhat Openstack | =10 | |
Redhat Openstack | =13 | |
Redhat Openstack | =14 | |
Debian Debian Linux | =10.0 | |
pip/nova | >=19.0.0<19.0.2 | 19.0.2 |
pip/nova | >=18.0.0<18.2.2 | 18.2.2 |
pip/nova | <17.0.12 | 17.0.12 |
debian/nova | 2:22.0.1-2+deb11u1 2:22.4.0-1~deb11u5 2:26.2.2-1~deb12u3 2:30.0.0-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14433 is a vulnerability in OpenStack Nova before version 17.0.12, 18.x before version 18.2.2, and 19.x before version 19.0.2.
The severity of CVE-2019-14433 is medium with a severity value of 6.5.
To fix CVE-2019-14433, you should update to OpenStack Nova version 17.0.12, 18.2.2, or 19.0.2 depending on your current version.
You can find more information about CVE-2019-14433 in the references section: [Link 1](http://www.openwall.com/lists/oss-security/2019/08/06/6), [Link 2](https://access.redhat.com/errata/RHSA-2019:2622), [Link 3](https://access.redhat.com/errata/RHSA-2019:2631).
The CWE (Common Weakness Enumeration) of CVE-2019-14433 is CWE-209.