Comment 43 for bug 1837877

Revision history for this message
Jeremy Stanley (fungi) wrote : Re: Error message reveals ceph information

A CVE assignment has been requested with MITRE using the following impact description:

Title: Nova Server Resource Faults Leak External Exception Details
Reporter: Donny Davis (Intel)
Products: Nova
Affects: <17.0.12,>=18.0.0<18.2.2,>=19.0.0<19.0.2

Description:
Donny Davis with Intel reported a vulnerability in Nova Compute
resource fault handling. If an API request from an authenticated
user ends in a fault condition due to an external exception, details
of the underlying environment may be leaked in the response and
could include sensitive configuration or other data.