GHSA-f4g4-cj8f-3cr9

Suggest an improvement
Source
https://github.com/advisories/GHSA-f4g4-cj8f-3cr9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-f4g4-cj8f-3cr9/GHSA-f4g4-cj8f-3cr9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-f4g4-cj8f-3cr9
Aliases
Published
2022-05-14T03:53:47Z
Modified
2024-05-19T02:24:41.558894Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
OpenStack Nova logs sensitive context from notification exceptions
Details

An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notification exception contexts appearing in ERROR level logs may include sensitive information such as account passwords and authorization tokens.

Database specific
{
    "nvd_published_at": "2017-03-21T18:59:00Z",
    "cwe_ids": [
        "CWE-532"
    ],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2024-05-14T21:13:46Z"
}
References

Affected packages

PyPI / nova

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
13.0.0
Fixed
13.1.4

PyPI / nova

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
14.0.0
Fixed
14.0.5

PyPI / nova

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
15.0.1
Fixed
15.0.2