First published: Mon Aug 19 2019(Updated: )
Donny Davis discovered that the Nova Compute service could return configuration or other information in response to a failed API request in some situations. A remote attacker could use this to expose sensitive information.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/nova-compute | <2:19.0.1-0ubuntu2.1 | 2:19.0.1-0ubuntu2.1 |
Ubuntu OpenSSH Client | =19.04 | |
All of | ||
ubuntu/python3-nova | <2:19.0.1-0ubuntu2.1 | 2:19.0.1-0ubuntu2.1 |
Ubuntu OpenSSH Client | =19.04 | |
All of | ||
ubuntu/nova-compute | <2:17.0.10-0ubuntu2.1 | 2:17.0.10-0ubuntu2.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/python-nova | <2:17.0.10-0ubuntu2.1 | 2:17.0.10-0ubuntu2.1 |
Ubuntu OpenSSH Client | =18.04 | |
All of | ||
ubuntu/nova-compute | <2:13.1.4-0ubuntu4.5 | 2:13.1.4-0ubuntu4.5 |
Ubuntu OpenSSH Client | =16.04 | |
All of | ||
ubuntu/python-nova | <2:13.1.4-0ubuntu4.5 | 2:13.1.4-0ubuntu4.5 |
Ubuntu OpenSSH Client | =16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is USN-4104-1.
Donny Davis discovered this vulnerability.
A remote attacker could use this vulnerability to expose sensitive information.
The Nova Compute service and the python3-nova package are affected.
Please update the affected software to version 2:19.0.1-0ubuntu2.1 or later.