OSSA-2019-003: Nova Server Resource Faults Leak External Exception Details¶
August 06, 2019
Donny Davis with Intel reported a vulnerability in Nova Compute resource fault handling. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response and could include sensitive configuration or other data.
Donny Davis from Intel (CVE-2019-14433)
The stable/ocata and stable/pike branches are under extended maintenance and will receive no new point releases, but patches for them are provided as a courtesy.