CVE-2024-7319: Openstack-heat: incomplete fix for cve-2023-1625
An incomplete fix for CVE-2023-1625 in openstack-heat was discovered. Some sensitive information may still be disclosed through openstack stack abandon command even with the hidden feature set to True and CVE-2023-1625 fix applied.
References:
https://storyboard.openstack.org/#!/story/2011007
Other sources
An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature set to True and the CVE-2023-1625 fix applied.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-7319?
The severity of CVE-2024-7319 has not been publicly disclosed, but it involves an incomplete fix for a prior vulnerability which may increase risk exposure.
How do I fix CVE-2024-7319?
Fixing CVE-2024-7319 requires upgrading to a patched version of openstack-heat beyond 22.0.1.
What does CVE-2024-7319 affect?
CVE-2024-7319 affects the openstack-heat package and multiple versions of the Red Hat OpenStack Platform.
What type of vulnerability is CVE-2024-7319?
CVE-2024-7319 is a vulnerability that allows potential sensitive information disclosure despite certain protections being in place.
Who is vulnerable to CVE-2024-7319?
Users running vulnerable versions of openstack-heat or specific versions of the Red Hat OpenStack Platform may be at risk from CVE-2024-7319.