An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Nova | Openstack | * | 17.0.12 (excluding) |
Nova | Openstack | 18.0.0 (including) | 18.2.2 (excluding) |
Nova | Openstack | 19.0.0 (including) | 19.0.2 (excluding) |
Red Hat OpenStack Platform 10.0 (Newton) | RedHat | openstack-nova-1:14.1.0-56.el7ost | * |
Red Hat OpenStack Platform 13.0 (Queens) | RedHat | openstack-nova-1:17.0.10-6.el7ost | * |
Red Hat OpenStack Platform 14.0 (Rocky) | RedHat | openstack-nova-1:18.2.1-0.20190509150817.8e130e2.el7ost | * |
Nova | Ubuntu | bionic | * |
Nova | Ubuntu | devel | * |
Nova | Ubuntu | disco | * |
Nova | Ubuntu | esm-infra/bionic | * |
Nova | Ubuntu | esm-infra/xenial | * |
Nova | Ubuntu | trusty | * |
Nova | Ubuntu | xenial | * |