CVE-2019-14433

EUVD-2019-0096
An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 79%
Affected Products (NVD)
VendorProductVersion
openstacknova
𝑥
< 17.0.12
openstacknova
18.0.0 ≤
𝑥
< 18.2.2
openstacknova
19.0.0 ≤
𝑥
< 19.0.2
canonicalubuntu_linux
16.04
canonicalubuntu_linux
18.04
canonicalubuntu_linux
19.04
debiandebian_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
nova
bookworm
2:26.2.2-1~deb12u3
fixed
bookworm (security)
2:26.2.2-1~deb12u3
fixed
bullseye
2:22.0.1-2+deb11u1
fixed
bullseye (security)
2:22.4.0-1~deb11u5
fixed
jessie
no-dsa
sid
2:30.0.0-1
fixed
stretch
no-dsa
trixie
2:30.0.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
nova
bionic
Fixed 2:17.0.10-0ubuntu2.1
released
disco
Fixed 2:19.0.1-0ubuntu2.1
released
trusty
dne
xenial
Fixed 2:13.1.4-0ubuntu4.5
released