CVE-2019-14433
openstack-nova: Nova server resource faults leak external exception details
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.
Se detectó un problema en OpenStack Nova en versiones anteriores a 17.0.12, versiones 18.x anteriores a 18.2.2, y versiones 19.x anteriores a 19.0.2. Si una petición de la API de un usuario autenticado termina en una condición de fallo debido a una excepción externa, los detalles del entorno subyacente puede ser filtrados en la respuesta, y podrían incluir una configuración confidencial u otros datos.
A vulnerability was found in the Nova Compute resource fault handling. The Nova Compute service might leak configuration information or other sensitive information because of a failed API request. To trigger this vulnerability, the API request needs to fail due to an external exception. The ability of an attacker to trigger an external exception in another component will determine the success of this attack.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-07-29 CVE Reserved
- 2019-08-09 CVE Published
- 2024-08-02 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-209: Generation of Error Message Containing Sensitive Information
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://www.openwall.com/lists/oss-security/2019/08/06/6 | Mailing List | |
https://lists.debian.org/debian-lts-announce/2022/09/msg00018.html | Mailing List |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://launchpad.net/bugs/1837877 | 2022-10-27 | |
https://security.openstack.org/ossa/OSSA-2019-003.html | 2022-10-27 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2019:2622 | 2022-10-27 | |
https://access.redhat.com/errata/RHSA-2019:2631 | 2022-10-27 | |
https://access.redhat.com/errata/RHSA-2019:2652 | 2022-10-27 | |
https://usn.ubuntu.com/4104-1 | 2022-10-27 | |
https://access.redhat.com/security/cve/CVE-2019-14433 | 2019-09-04 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1735522 | 2019-09-04 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Openstack Search vendor "Openstack" | Nova Search vendor "Openstack" for product "Nova" | < 17.0.12 Search vendor "Openstack" for product "Nova" and version " < 17.0.12" | - |
Affected
| ||||||
Openstack Search vendor "Openstack" | Nova Search vendor "Openstack" for product "Nova" | >= 18.0.0 < 18.2.2 Search vendor "Openstack" for product "Nova" and version " >= 18.0.0 < 18.2.2" | - |
Affected
| ||||||
Openstack Search vendor "Openstack" | Nova Search vendor "Openstack" for product "Nova" | >= 19.0.0 < 19.0.2 Search vendor "Openstack" for product "Nova" and version " >= 19.0.0 < 19.0.2" | - |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 16.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "16.04" | esm |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 18.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "18.04" | lts |
Affected
| ||||||
Canonical Search vendor "Canonical" | Ubuntu Linux Search vendor "Canonical" for product "Ubuntu Linux" | 19.04 Search vendor "Canonical" for product "Ubuntu Linux" and version "19.04" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openstack Search vendor "Redhat" for product "Openstack" | 10 Search vendor "Redhat" for product "Openstack" and version "10" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openstack Search vendor "Redhat" for product "Openstack" | 13 Search vendor "Redhat" for product "Openstack" and version "13" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Openstack Search vendor "Redhat" for product "Openstack" | 14 Search vendor "Redhat" for product "Openstack" and version "14" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
|