5
CVSSv2

CVE-2017-7214

Published: 21/03/2017 Updated: 05/01/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists in exception_wrapper.py in OpenStack Nova 13.x up to and including 13.1.3, 14.x up to and including 14.0.4, and 15.x up to and including 15.0.1. Legacy notification exception contexts appearing in ERROR level logs may include sensitive information such as account passwords and authorization tokens.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack nova 15.0.0

openstack nova 15.0.1

openstack nova 13.1.2

openstack nova 13.1.1

openstack nova 14.0.3

openstack nova 14.0.4

openstack nova 14.0.0

openstack nova 13.1.3

openstack nova 14.0.1

openstack nova 14.0.2

openstack nova 13.1.0

openstack nova 13.0.0

Vendor Advisories

Debian Bug report logs - #858568 nova: CVE-2017-7214 Package: src:nova; Maintainer for src:nova is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 23 Mar 2017 18:39:02 UTC Severity: important Tags: patch, security, upstream Found in version nova/ ...
Synopsis Moderate: openstack-nova security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for openstack-nova is now available for Red Hat OpenStack Platform 90 (Mitaka)Red Hat Product Security has rated this update as having a security impact of Moderate A Comm ...
Synopsis Moderate: openstack-nova and python-novaclient security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for openstack-nova and python-novaclient is now available for Red Hat OpenStack Platform 100 (Newton)Red Hat Product Security has rated this update as ...