First published: Wed Jan 17 2024(Updated: )
An incomplete fix for <a href="https://access.redhat.com/security/cve/CVE-2023-1625">CVE-2023-1625</a> in openstack-heat was discovered. Some sensitive information may still be disclosed through openstack stack abandon command even with the hidden feature set to True and <a href="https://access.redhat.com/security/cve/CVE-2023-1625">CVE-2023-1625</a> fix applied. References: <a href="https://storyboard.openstack.org/#!/story/2011007">https://storyboard.openstack.org/#!/story/2011007</a>
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
pip/openstack-heat | <=22.0.1 | |
openstack heat | ||
redhat openstack platform | =13.0 | |
redhat openstack platform | =16.1 | |
redhat openstack platform | =16.2 | |
redhat openstack platform | =17.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-7319 has not been publicly disclosed, but it involves an incomplete fix for a prior vulnerability which may increase risk exposure.
Fixing CVE-2024-7319 requires upgrading to a patched version of openstack-heat beyond 22.0.1.
CVE-2024-7319 affects the openstack-heat package and multiple versions of the Red Hat OpenStack Platform.
CVE-2024-7319 is a vulnerability that allows potential sensitive information disclosure despite certain protections being in place.
Users running vulnerable versions of openstack-heat or specific versions of the Red Hat OpenStack Platform may be at risk from CVE-2024-7319.