CVE-2019-14433

Source
https://cve.org/CVERecord?id=CVE-2019-14433
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-14433.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-14433
Aliases
Downstream
Published
2019-08-09T19:15:11.577Z
Modified
2026-04-09T06:29:11.426595Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.

References

Affected packages

Git / github.com/openstack/nova

Affected ranges

Type
GIT
Repo
https://github.com/openstack/nova
Events
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "17.0.12"
        },
        {
            "introduced": "18.0.0"
        },
        {
            "fixed": "18.2.2"
        },
        {
            "introduced": "19.0.0"
        },
        {
            "fixed": "19.0.2"
        }
    ]
}

Affected versions

0.*
0.9.0
12.*
12.0.0.0b1
12.0.0.0b2
12.0.0.0b3
12.0.0.0rc1
12.0.0a0
13.*
13.0.0.0b1
13.0.0.0b2
13.0.0.0b3
13.0.0.0rc1
14.*
14.0.0.0b1
14.0.0.0b2
14.0.0.0b3
14.0.0.0rc1
15.*
15.0.0.0b1
15.0.0.0b2
15.0.0.0b3
15.0.0.0rc1
16.*
16.0.0.0b1
16.0.0.0b2
16.0.0.0b3
16.0.0.0rc1
17.*
17.0.0
17.0.0.0b1
17.0.0.0b2
17.0.0.0b3
17.0.0.0rc1
17.0.0.0rc2
17.0.0.0rc3
17.0.1
17.0.10
17.0.11
17.0.2
17.0.3
17.0.4
17.0.5
17.0.6
17.0.7
17.0.8
17.0.9
18.*
18.0.0
18.0.0.0rc3
18.0.1
18.0.2
18.0.3
18.1.0
18.2.0
18.2.1
19.*
19.0.0
19.0.0.0rc2
19.0.1
2010.*
2010.1
2011.*
2011.1
2011.1rc1
2011.2
2011.2gamma1
2011.2rc1
2013.*
2013.1.rc1
2013.2.b3
2013.2.rc1
2014.*
2014.1.b1
2014.1.b2
2014.1.b3
2014.1.rc1
2014.2.b1
2014.2.b2
2014.2.b3
2014.2.rc1
2015.*
2015.1.0b1
2015.1.0b2
2015.1.0b3
2015.1.0rc1
Other
diablo-1
essex-1
folsom-1
folsom-2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-14433.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "16.04"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "18.04"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "19.04"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "10"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "13"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "14"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "10.0"
            }
        ]
    }
]