Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-14433

Опубликовано: 09 авг. 2019
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*
Версия до 17.0.12 (исключая)
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*
Версия от 18.0.0 (включая) до 18.2.2 (исключая)
cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*
Версия от 19.0.0 (включая) до 19.0.2 (исключая)
Конфигурация 2

Одно из

cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*
Конфигурация 3

Одно из

cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:14:*:*:*:*:*:*:*
Конфигурация 4
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 80%
0.01327
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-209

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 6 лет назад

An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.

CVSS3: 6.5
redhat
больше 6 лет назад

An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.

CVSS3: 6.5
debian
больше 6 лет назад

An issue was discovered in OpenStack Nova before 17.0.12, 18.x before ...

CVSS3: 6.5
github
больше 3 лет назад

OpenStack Nova Server Resource Faults Leak External Exception Details

EPSS

Процентиль: 80%
0.01327
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-209