4
CVSSv2

CVE-2019-14433

Published: 09/08/2019 Updated: 27/10/2022
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

An issue exists in OpenStack Nova prior to 17.0.12, 18.x prior to 18.2.2, and 19.x prior to 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack nova

canonical ubuntu linux 18.04

canonical ubuntu linux 19.04

canonical ubuntu linux 16.04

redhat openstack 10

redhat openstack 14

redhat openstack 13

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #934114 nova: CVE-2019-14433 Package: src:nova; Maintainer for src:nova is Debian OpenStack <team+openstack@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 7 Aug 2019 07:39:02 UTC Severity: important Tags: security, upstream Found in version nova/2:190 ...
Nova could be made to expose sensitive information ...
Synopsis Moderate: openstack-nova security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for openstack-nova is now available for Red Hat OpenStack Platform 140 (Rocky)Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerabili ...
Synopsis Moderate: openstack-nova security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for openstack-nova is now available for Red Hat OpenStack Platform 100 (Newton)Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerabil ...
Synopsis Moderate: openstack-nova security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for openstack-nova is now available for Red Hat OpenStack Platform 130 (Queens)Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerabil ...
Impact: Moderate Public Date: 2019-08-06 CWE: CWE-209 Bugzilla: 1735522: CVE-2019-14433 openstack-nova: ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> oss-sec mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> [OSSA-2019-003] Nova Server Resource Faults Leak External Exception Details (CVE-2019-14433) <!--X-Subject-Header-End--> <!--X ...