CVE-2019-14433

An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:14:*:*:*:*:*:*:*

Configuration 4 (hide)

cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

History

21 Nov 2024, 04:26

Type Values Removed Values Added
References () http://www.openwall.com/lists/oss-security/2019/08/06/6 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2019/08/06/6 - Mailing List, Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2019:2622 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2019:2622 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2019:2631 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2019:2631 - Third Party Advisory
References () https://access.redhat.com/errata/RHSA-2019:2652 - Third Party Advisory () https://access.redhat.com/errata/RHSA-2019:2652 - Third Party Advisory
References () https://launchpad.net/bugs/1837877 - Issue Tracking, Patch, Third Party Advisory () https://launchpad.net/bugs/1837877 - Issue Tracking, Patch, Third Party Advisory
References () https://lists.debian.org/debian-lts-announce/2022/09/msg00018.html - Mailing List, Third Party Advisory () https://lists.debian.org/debian-lts-announce/2022/09/msg00018.html - Mailing List, Third Party Advisory
References () https://security.openstack.org/ossa/OSSA-2019-003.html - Patch, Vendor Advisory () https://security.openstack.org/ossa/OSSA-2019-003.html - Patch, Vendor Advisory
References () https://usn.ubuntu.com/4104-1/ - Third Party Advisory () https://usn.ubuntu.com/4104-1/ - Third Party Advisory

Information

Published : 2019-08-09 19:15

Updated : 2024-11-21 04:26


NVD link : CVE-2019-14433

Mitre link : CVE-2019-14433

CVE.ORG link : CVE-2019-14433


JSON object : View

Products Affected

canonical

  • ubuntu_linux

redhat

  • openstack

openstack

  • nova

debian

  • debian_linux
CWE
CWE-209

Generation of Error Message Containing Sensitive Information