Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f4g4-cj8f-3cr9

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

OpenStack Nova logs sensitive context from notification exceptions

An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notification exception contexts appearing in ERROR level logs may include sensitive information such as account passwords and authorization tokens.

Пакеты

Наименование

nova

pip
Затронутые версииВерсия исправления

>= 13.0.0, < 13.1.4

13.1.4

Наименование

nova

pip
Затронутые версииВерсия исправления

>= 14.0.0, < 14.0.5

14.0.5

Наименование

nova

pip
Затронутые версииВерсия исправления

>= 15.0.1, < 15.0.2

15.0.2

EPSS

Процентиль: 79%
0.01297
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notification exception contexts appearing in ERROR level logs may include sensitive information such as account passwords and authorization tokens.

CVSS3: 6.1
redhat
почти 9 лет назад

An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notification exception contexts appearing in ERROR level logs may include sensitive information such as account passwords and authorization tokens.

CVSS3: 9.8
nvd
почти 9 лет назад

An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notification exception contexts appearing in ERROR level logs may include sensitive information such as account passwords and authorization tokens.

CVSS3: 9.8
debian
почти 9 лет назад

An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x ...

EPSS

Процентиль: 79%
0.01297
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-532