Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-7214

Опубликовано: 21 мар. 2017
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notification exception contexts appearing in ERROR level logs may include sensitive information such as account passwords and authorization tokens.

An information exposure issue was discovered in OpenStack Compute's exception_wrapper.py. Legacy notification exception contexts appearing in ERROR-level logs could include sensitive information such as account passwords and authorization tokens.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)openstack-novaNot affected
Red Hat Enterprise Linux OpenStack Platform 6 (Juno)openstack-novaNot affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)openstack-novaNot affected
Red Hat OpenStack Platform 11 (Ocata)openstack-novaNot affected
Red Hat OpenStack Platform 8 (Liberty)openstack-novaNot affected
Red Hat OpenStack Platform 10.0 (Newton)openstack-novaFixedRHSA-2017:159528.06.2017
Red Hat OpenStack Platform 10.0 (Newton)python-novaclientFixedRHSA-2017:159528.06.2017
Red Hat OpenStack Platform 9.0 (Mitaka)openstack-novaFixedRHSA-2017:150819.06.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1434844openstack-nova: Sensitive information included in legacy notification exception contexts

EPSS

Процентиль: 79%
0.01297
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 9 лет назад

An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notification exception contexts appearing in ERROR level logs may include sensitive information such as account passwords and authorization tokens.

CVSS3: 9.8
nvd
почти 9 лет назад

An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notification exception contexts appearing in ERROR level logs may include sensitive information such as account passwords and authorization tokens.

CVSS3: 9.8
debian
почти 9 лет назад

An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x ...

CVSS3: 9.8
github
больше 3 лет назад

OpenStack Nova logs sensitive context from notification exceptions

EPSS

Процентиль: 79%
0.01297
Низкий

6.1 Medium

CVSS3