Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pg64-r7rr-phv8

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

OpenStack Nova Server Resource Faults Leak External Exception Details

An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.

Пакеты

Наименование

nova

pip
Затронутые версииВерсия исправления

< 17.0.12

17.0.12

Наименование

nova

pip
Затронутые версииВерсия исправления

>= 18.0.0, < 18.2.2

18.2.2

Наименование

nova

pip
Затронутые версииВерсия исправления

>= 19.0.0, < 19.0.2

19.0.2

EPSS

Процентиль: 80%
0.01327
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-209

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 6 лет назад

An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.

CVSS3: 6.5
redhat
больше 6 лет назад

An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.

CVSS3: 6.5
nvd
больше 6 лет назад

An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.

CVSS3: 6.5
debian
больше 6 лет назад

An issue was discovered in OpenStack Nova before 17.0.12, 18.x before ...

EPSS

Процентиль: 80%
0.01327
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-209