First published: Wed Jan 17 2024(Updated: )
An incomplete fix for <a href="https://access.redhat.com/security/cve/CVE-2023-1625">CVE-2023-1625</a> in openstack-heat was discovered. Some sensitive information may still be disclosed through openstack stack abandon command even with the hidden feature set to True and <a href="https://access.redhat.com/security/cve/CVE-2023-1625">CVE-2023-1625</a> fix applied. References: <a href="https://storyboard.openstack.org/#!/story/2011007">https://storyboard.openstack.org/#!/story/2011007</a>
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack Heat |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2258810 is high due to potential disclosure of sensitive information.
To fix REDHAT-BUG-2258810, apply the latest patch or update for OpenStack Heat provided by your distribution.
All versions of OpenStack Heat that do not have the fix for CVE-2023-1625 are affected by REDHAT-BUG-2258810.
Yes, sensitive data may be at risk of disclosure when the openstack stack abandon command is executed.
If you cannot update OpenStack Heat, consider temporarily disabling the functionality that uses the stack abandon command until a fix can be applied.