Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-7319

Опубликовано: 31 июл. 2024
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature set to True and the CVE-2023-1625 fix applied.

Отчет

While this flaw leaks a password, which could reduce confidentiality, integrity, and availability, the impact to this triad is rated Low. This is because OpenStack can not be more broadly compromised for two reasons: a) The host has separate authorization authority from the guest virtual machine b) The guest virtual machines that are configured by different stack configurations cannot be compromised Therefore, the overall impact of the flaw is rated Moderate.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 13 (Queens)openstack-heatOut of support scope
Red Hat OpenStack Platform 16.1openstack-heatWill not fix
Red Hat OpenStack Platform 16.2openstack-heatWill not fix
Red Hat OpenStack Platform 17.0openstack-heatAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=2258810openstack-heat: Incomplete fix for CVE-2023-1625

EPSS

Процентиль: 66%
0.00507
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5
ubuntu
больше 1 года назад

An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature set to True and the CVE-2023-1625 fix applied.

CVSS3: 5
nvd
больше 1 года назад

An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature set to True and the CVE-2023-1625 fix applied.

CVSS3: 5
debian
больше 1 года назад

An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensi ...

CVSS3: 5
github
больше 1 года назад

openstack-heat may disclose sensitive information

EPSS

Процентиль: 66%
0.00507
Низкий

5 Medium

CVSS3