An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notification exception contexts appearing in ERROR level logs may include sensitive information such as account passwords and authorization tokens.
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade python-novaclient | Aug 28, 2019 | Mar 21, 2017 |
| Debian | — | Upgrade nova | Jul 30, 2024 | Mar 21, 2017 |
| Oracle Solaris | — | Upgrade cloud/openstack/nova to version 0.2015.1.2-0.175.3.20.0.2.0 on Solaris 11.3 | May 29, 2017 | Mar 21, 2017 |
| Redhat_linux | — | Upgrade python-novaclient | Oct 4, 2017 | Mar 21, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub