CVE-2023-1625
published 2024-08-02CVE-2023-1625: An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command…
PriorityP428medium5CVSS 3.1
AVNACLPRLUINSCCLINAN
EPSS
0.71%
49.7th percentile
An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature set to True and the CVE-2023-1625 fix applied.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | heat | < heat 1:19.0.0-2 (bookworm) | heat 1:19.0.0-2 (bookworm) |
| debian | heat | — | — |
| juniper | junos_os | — | — |
| linux | linux_kernel | >= 5.11.0 < 5.15.111 | 5.15.111 |
| linux | linux_kernel | >= 5.16.0 < 6.1.28 | 6.1.28 |
| linux | linux_kernel | >= 5.6.0 < 5.10.180 | 5.10.180 |
| linux | linux_kernel | >= 6.2.0 < 6.2.15 | 6.2.15 |
| linux | linux_kernel | >= 6.3.0 < 6.3.2 | 6.3.2 |
| openstack | heat | >= 0 < 1:19.0.0-2 | 1:19.0.0-2 |
| openstack | heat | >= 0 < 1:19.0.0-2 | 1:19.0.0-2 |
| openstack | heat | >= 0 < 1:19.0.0-2 | 1:19.0.0-2 |
| redhat | openstack_platform | — | — |
| redhat | openstack_platform | — | — |
| redhat | openstack_platform | — | — |
| redhat | openstack_platform | — | — |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
ghsa5.0MEDIUM
osv5.0MEDIUM
vendor_debian7.4HIGH
vendor_redhat7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: f2fs: compress: fix to call f2fs_wait_on_page_writeback() in f2fs_write_raw_pages()
vendor_redhat·2025-12-24
CVE-2023-54068 kernel: f2fs: compress: fix to call f2fs_wait_on_page_writeback() in f2fs_write_raw_pages()
kernel: f2fs: compress: fix to call f2fs_wait_on_page_writeback() in f2fs_write_raw_pages()
In the Linux kernel, the following vulnerability has been resolved:
f2fs: compress: fix to call f2fs_wait_on_page_writeback() in f2fs_write_raw_pages()
BUG_ON() will be triggered when writing files concurrently,
because the same page is writtenback multiple times.
1597 void folio_end_writeback(struct folio *folio)
1598 {
......
1618 if (!__folio_end_writeback(folio))
1619 BUG();
......
1625 }
kernel BUG at mm/filemap.c:1619!
Call Trace:
f2fs_write_end_io+0x1a0/0x370
blk_update_request+0x6c/0x410
blk_mq_end_request+0x15/0x130
blk_complete_reqs+0x3c/0x50
__do_softirq+0xb8/0x29b
? sort_range+0x20/0x20
run_ksoftirqd+0x19/0x20
smpboot_thread_fn+0x10b/0x1d0
kthread+0xde/0x110
? kthread_complete_and_exit
Red Hat
openstack-heat: Incomplete fix for CVE-2023-1625
vendor_redhat·2024-07-31·CVSS 7.4
CVE-2024-7319 [HIGH] CWE-200 openstack-heat: Incomplete fix for CVE-2023-1625
openstack-heat: Incomplete fix for CVE-2023-1625
An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature set to True and the CVE-2023-1625 fix applied.
An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature set to True and the CVE-2023-1625 fix applied.
Statement: While this flaw leaks a password, which could reduce confidentiality, integrity, and availability, the impact to this triad is rated Low. This is because OpenStack can not be more broadly compromised for two reasons:
a) The host has separate authorization authority from the guest
Debian
CVE-2024-7319: heat - An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive infor...
vendor_debian·2024·CVSS 7.4
CVE-2024-7319 [HIGH] CVE-2024-7319: heat - An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive infor...
An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature set to True and the CVE-2023-1625 fix applied.
Scope: local
bookworm: open
bullseye: resolved
forky: open
sid: open
trixie: open
Ubuntu
OpenStack Heat vulnerability
vendor_ubuntu·2023-08-16
CVE-2023-1625 OpenStack Heat vulnerability
Title: OpenStack Heat vulnerability
Summary: OpenStack Heat could be made to expose sensitive information.
It was discovered that OpenStack Heat incorrectly handled certain hidden
parameter values. A remote authenticated user could possibly use this issue
to obtain sensitive data.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openstack-heat: information leak in API
vendor_redhat·2023-01-27·CVSS 7.4
CVE-2023-1625 [HIGH] CWE-202 openstack-heat: information leak in API
openstack-heat: information leak in API
An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.
An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.
Statement: While this flaw leaks a password which could reduce confidentiality, integrity, and availability, the impact to this triad is rated low. This is because OpenStack can n
Debian
CVE-2023-1625: heat - An information leak was discovered in OpenStack heat. This issue could allow a r...
vendor_debian·2023·CVSS 7.4
CVE-2023-1625 [HIGH] CVE-2023-1625: heat - An information leak was discovered in OpenStack heat. This issue could allow a r...
An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.
Scope: local
bookworm: resolved (fixed in 1:19.0.0-2)
bullseye: open
forky: resolved (fixed in 1:19.0.0-2)
sid: resolved (fixed in 1:19.0.0-2)
trixie: resolved (fixed in 1:19.0.0-2)
OSV
f2fs: compress: fix to call f2fs_wait_on_page_writeback() in f2fs_write_raw_pages()
osv·2025-12-24
CVE-2023-54068 f2fs: compress: fix to call f2fs_wait_on_page_writeback() in f2fs_write_raw_pages()
f2fs: compress: fix to call f2fs_wait_on_page_writeback() in f2fs_write_raw_pages()
In the Linux kernel, the following vulnerability has been resolved:
f2fs: compress: fix to call f2fs_wait_on_page_writeback() in f2fs_write_raw_pages()
BUG_ON() will be triggered when writing files concurrently,
because the same page is writtenback multiple times.
1597 void folio_end_writeback(struct folio *folio)
1598 {
......
1618 if (!__folio_end_writeback(folio))
1619 BUG();
......
1625 }
kernel BUG at mm/filemap.c:1619!
Call Trace:
f2fs_write_end_io+0x1a0/0x370
blk_update_request+0x6c/0x410
blk_mq_end_request+0x15/0x130
blk_complete_reqs+0x3c/0x50
__do_softirq+0xb8/0x29b
? sort_range+0x20/0x20
run_ksoftirqd+0x19/0x20
smpboot_thread_fn+0x10b/0x1d0
kthread+0xde/0x110
? kthread_complete_and_exit+0x2
GHSA
openstack-heat may disclose sensitive information
ghsa·2024-08-02·CVSS 5.0
CVE-2024-7319 [MEDIUM] CWE-200 openstack-heat may disclose sensitive information
openstack-heat may disclose sensitive information
An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature set to True and the CVE-2023-1625 fix applied.
OSV
CVE-2024-7319: An incomplete fix for CVE-2023-1625 was found in openstack-heat
osv·2024-08-02·CVSS 5.0
CVE-2024-7319 [MEDIUM] CVE-2024-7319: An incomplete fix for CVE-2023-1625 was found in openstack-heat
An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature set to True and the CVE-2023-1625 fix applied.
OSV
openstack-heat may disclose sensitive information
osv·2024-08-02·CVSS 5.0
CVE-2024-7319 [MEDIUM] openstack-heat may disclose sensitive information
openstack-heat may disclose sensitive information
An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature set to True and the CVE-2023-1625 fix applied.
OSV
OpenStack Heat information leak vulnerability
osv·2023-09-24
CVE-2023-1625 [HIGH] OpenStack Heat information leak vulnerability
OpenStack Heat information leak vulnerability
An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.
GHSA
OpenStack Heat information leak vulnerability
ghsa·2023-09-24
CVE-2023-1625 [HIGH] CWE-200 OpenStack Heat information leak vulnerability
OpenStack Heat information leak vulnerability
An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.
OSV
CVE-2023-1625: An information leak was discovered in OpenStack heat
osv·2023-09-24·CVSS 5.0
CVE-2023-1625 [MEDIUM] CVE-2023-1625: An information leak was discovered in OpenStack heat
An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.
No detection rules found.
No public exploits indexed.
2024-08-02
Published