[OSSA-2019-003] Nova Server Resource Faults Leak External Exception Details (CVE-2019-14433)
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Compute (nova) |
Fix Released
|
High
|
Matt Riedemann | ||
Ocata |
Fix Committed
|
High
|
Matt Riedemann | ||
Pike |
Fix Released
|
High
|
Matt Riedemann | ||
Queens |
Fix Committed
|
High
|
Matt Riedemann | ||
Rocky |
Fix Committed
|
High
|
Matt Riedemann | ||
Stein |
Fix Committed
|
High
|
Matt Riedemann | ||
OpenStack Security Advisory |
Fix Released
|
High
|
Jeremy Stanley |
Bug Description
It would appear Nova is revealing information that may be sensitive in error messages
http://
I attempted to hard-reboot it, and it went into an error state. The
initial error in the server status was
{'message': 'Timed out during operation: cannot acquire state change lock (held by monitor=
After a short period, I tried again and got a different error state
{'message': "internal error: process exited while connecting to monitor: lc=,keyid=
I don't know if this is a setting or a bug. Better to report and close than not say anything I guess.
CVE References
Changed in ossa: | |
status: | Incomplete → Triaged |
importance: | Undecided → High |
assignee: | nobody → Jeremy Stanley (fungi) |
summary: |
- Error message reveals ceph information + Nova Server Resource Faults Leak External Exception Details + (CVE-2019-14433) |
information type: | Private Security → Public Security |
summary: |
- Nova Server Resource Faults Leak External Exception Details - (CVE-2019-14433) + [OSSA-2019-003] Nova Server Resource Faults Leak External Exception + Details (CVE-2019-14433) |
description: | updated |
Since this report concerns a possible security risk, an incomplete security advisory task has been added while the core security reviewers for the affected project or projects confirm the bug and discuss the scope of any vulnerability along with potential solutions.