CVE-2019-14433
published 2019-08-09CVE-2019-14433: An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a…
PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.93%
77.7th percentile
An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | nova | < nova 2:19.0.2-1 (bookworm) | nova 2:19.0.2-1 (bookworm) |
| openstack | nova | < 17.0.12 | 17.0.12 |
| openstack | nova | >= 0 < 2:19.0.2-1 | 2:19.0.2-1 |
| openstack | nova | >= 0 < 2:19.0.2-1 | 2:19.0.2-1 |
| openstack | nova | >= 0 < 2:19.0.2-1 | 2:19.0.2-1 |
| openstack | nova | >= 0 < 2:19.0.2-1 | 2:19.0.2-1 |
| openstack | nova | >= 0 < 17.0.12 | 17.0.12 |
| openstack | nova | >= 18.0.0 < 18.2.2 | 18.2.2 |
| openstack | nova | >= 18.0.0 < 18.2.2 | 18.2.2 |
| openstack | nova | >= 19.0.0 < 19.0.2 | 19.0.2 |
| openstack | nova | >= 19.0.0 < 19.0.2 | 19.0.2 |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Nova vulnerability
vendor_ubuntu·2019-08-19
CVE-2019-14433 Nova vulnerability
Title: Nova vulnerability
Summary: Nova could be made to expose sensitive information.
Donny Davis discovered that the Nova Compute service could return
configuration or other information in response to a failed API
request in some situations. A remote attacker could use this to expose
sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openstack-nova: Nova server resource faults leak external exception details
vendor_redhat·2019-08-06·CVSS 6.5
CVE-2019-14433 [MEDIUM] CWE-209 openstack-nova: Nova server resource faults leak external exception details
openstack-nova: Nova server resource faults leak external exception details
An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.
A vulnerability was found in the Nova Compute resource fault handling. The Nova Compute service might leak configuration information or other sensitive information because of a failed API request. To trigger this vulnerability, the API request needs to fail due to an external exception. The ability of an attacker to trigger an external exception in another component will determine the succe
Debian
CVE-2019-14433: nova - An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, an...
vendor_debian·2019·CVSS 6.5
CVE-2019-14433 [MEDIUM] CVE-2019-14433: nova - An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, an...
An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.
Scope: local
bookworm: resolved (fixed in 2:19.0.2-1)
bullseye: resolved (fixed in 2:19.0.2-1)
forky: resolved (fixed in 2:19.0.2-1)
sid: resolved (fixed in 2:19.0.2-1)
trixie: resolved (fixed in 2:19.0.2-1)
GHSA
OpenStack Nova Server Resource Faults Leak External Exception Details
ghsa·2022-05-24
CVE-2019-14433 [HIGH] CWE-200 OpenStack Nova Server Resource Faults Leak External Exception Details
OpenStack Nova Server Resource Faults Leak External Exception Details
An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.
OSV
OpenStack Nova Server Resource Faults Leak External Exception Details
osv·2022-05-24
CVE-2019-14433 [HIGH] OpenStack Nova Server Resource Faults Leak External Exception Details
OpenStack Nova Server Resource Faults Leak External Exception Details
An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.
OSV
CVE-2019-14433: An issue was discovered in OpenStack Nova before 17
osv·2019-08-09·CVSS 6.5
CVE-2019-14433 [MEDIUM] CVE-2019-14433: An issue was discovered in OpenStack Nova before 17
An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-14433 openstack-nova: Nova server resource faults leak external exception details [openstack-rdo]
bugzilla·2019-08-06·CVSS 6.5
CVE-2019-14433 [MEDIUM] CVE-2019-14433 openstack-nova: Nova server resource faults leak external exception details [openstack-rdo]
CVE-2019-14433 openstack-nova: Nova server resource faults leak external exception details [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
https:/
Bugzilla
CVE-2019-14433 openstack-nova: Nova server resource faults leak external exception details
bugzilla·2019-08-01·CVSS 6.5
CVE-2019-14433 [MEDIUM] CVE-2019-14433 openstack-nova: Nova server resource faults leak external exception details
CVE-2019-14433 openstack-nova: Nova server resource faults leak external exception details
A vulnerability was found in Nova Compute resource fault handling. If an API request from an authenticateduser ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response and could include sensitive configuration or other data.
Discussion:
Upstream bug: https://bugs.launchpad.net/nova/+bug/1837877
---
Acknowledgments:
Name: The OpenStack project
---
External References:
https://security.openstack.org/ossa/OSSA-2019-003.html
---
Created openstack-nova tracking bugs for this issue:
Affects: openstack-rdo [bug 1738351]
---
Statement:
Red Hat OpenStack Platform 9 will be retired shortly after the flaw's public date; based on t
http://www.openwall.com/lists/oss-security/2019/08/06/6https://access.redhat.com/errata/RHSA-2019:2622https://access.redhat.com/errata/RHSA-2019:2631https://access.redhat.com/errata/RHSA-2019:2652https://launchpad.net/bugs/1837877https://lists.debian.org/debian-lts-announce/2022/09/msg00018.htmlhttps://security.openstack.org/ossa/OSSA-2019-003.htmlhttps://usn.ubuntu.com/4104-1/http://www.openwall.com/lists/oss-security/2019/08/06/6https://access.redhat.com/errata/RHSA-2019:2622https://access.redhat.com/errata/RHSA-2019:2631https://access.redhat.com/errata/RHSA-2019:2652https://launchpad.net/bugs/1837877https://lists.debian.org/debian-lts-announce/2022/09/msg00018.htmlhttps://security.openstack.org/ossa/OSSA-2019-003.htmlhttps://usn.ubuntu.com/4104-1/
2019-08-09
Published