CVE-2017-7214

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-7214
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-7214.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2017-7214
Aliases
Downstream
Related
Published
2017-03-21T18:59:00.167Z
Modified
2025-11-14T05:16:37.265058Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notification exception contexts appearing in ERROR level logs may include sensitive information such as account passwords and authorization tokens.

References

Affected packages

Git / github.com/openstack/nova

Affected versions

0.*

0.9.0

12.*

12.0.0
12.0.0.0b1
12.0.0.0b2
12.0.0.0b3
12.0.0.0rc1
12.0.0.0rc2
12.0.0.0rc3
12.0.0a0

13.*

13.0.0
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
13.0.0.0rc2
13.0.0.0rc3

2010.*

2010.1

2011.*

2011.1
2011.1rc1
2011.2
2011.2gamma1
2011.2rc1

2013.*

2013.1.rc1
2013.2.b3
2013.2.rc1

2014.*

2014.1.b1
2014.1.b2
2014.1.b3
2014.1.rc1
2014.2
2014.2.b1
2014.2.b2
2014.2.b3
2014.2.rc1
2014.2.rc2

2015.*

2015.1.0
2015.1.0b1
2015.1.0b2
2015.1.0b3
2015.1.0rc1
2015.1.0rc2
2015.1.0rc3

Other

diablo-1
diablo-2
essex-1
folsom-1
folsom-2