An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Link | Tags |
---|---|
https://launchpad.net/bugs/1837877 | patch third party advisory issue tracking |
https://security.openstack.org/ossa/OSSA-2019-003.html | patch vendor advisory |
http://www.openwall.com/lists/oss-security/2019/08/06/6 | third party advisory mailing list |
https://usn.ubuntu.com/4104-1/ | third party advisory vendor advisory |
https://access.redhat.com/errata/RHSA-2019:2631 | third party advisory vendor advisory |
https://access.redhat.com/errata/RHSA-2019:2622 | third party advisory vendor advisory |
https://access.redhat.com/errata/RHSA-2019:2652 | third party advisory vendor advisory |
https://lists.debian.org/debian-lts-announce/2022/09/msg00018.html | third party advisory mailing list |