SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-14433

If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.

MEDIUM 6.5EPSS 1.94%

Does this matter?

Lower severity and a low EPSS score (1.94%). Track it; it rarely justifies an emergency change on its own.

Description

An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
1.94% probability · 79th percentile
CISA KEV
Not listed
Weakness
CWE-209
Affected
openstack/nova · canonical/ubuntu linux · redhat/openstack · debian/debian linux
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.