An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature set to True and the CVE-2023-1625 fix applied.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "13.0"
},
{
"introduced": "0"
},
{
"last_affected": "16.1"
},
{
"introduced": "0"
},
{
"last_affected": "17.0"
}
]
}