OSSA-2017-002: Nova logs sensitive context from notification exceptions

Date:March 23, 2017
CVE:CVE-2017-7214

Affects

  • Nova: >=13.0.0 <=13.1.3, >=14.0.0 <=14.0.4, >=15.0.0 <=15.0.1

Description

Matt Riedemann with Huawei reported a vulnerability in Nova. Legacy notification exception contexts appearing in ERROR level logs may include sensitive information such as account passwords and authorization tokens. All Nova setups are affected.

Credits

  • Matt Riedemann from Huawei (CVE-2017-7214)