6.5
CVE-2019-14433
- EPSS 1.94%
- Veröffentlicht 09.08.2019 19:15:11
- Zuletzt bearbeitet 21.11.2024 04:26:44
- Erkennungen
An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.04
Debian ≫ Debian Linux Version 10.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.94% | 0.782 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| NIST | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
CWE-209 Generation of Error Message Containing Sensitive Information
The product generates an error message that includes sensitive information about its environment, users, or associated data.
http://www.openwall.com/lists/oss-security/2019/08/06/6
https://access.redhat.com/errata/RHSA-2019:2622
https://access.redhat.com/errata/RHSA-2019:2631
https://access.redhat.com/errata/RHSA-2019:2652
https://launchpad.net/bugs/1837877
https://lists.debian.org/debian-lts-announce/2022/09/msg00018.html
https://security.openstack.org/ossa/OSSA-2019-003.html
https://usn.ubuntu.com/4104-1/