Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-7319
HistoryAug 02, 2024 - 12:00 a.m.

CVE-2024-7319

2024-08-0200:00:00
ubuntu.com
ubuntu.com
1
openstack
heat
sensitive information
disclosure
unix

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

EPSS

0.001

Percentile

32.6%

An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive
information may possibly be disclosed through the OpenStack stack abandon
command with the hidden feature set to True and the CVE-2023-1625 fix
applied.

Bugs

Notes

Author Note
mdeslaur See openstack bug, there isn’t likely to be a fix available for this issue. This vulnerability requires the “Abandon” feature to be enabled, while it is disabled by default. Fixing this will also break the “Adopt” feature, which is also disabled by default. As of 2024-08-16, there is no fix for this issue available from heat developers.

CVSS3

7.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L

EPSS

0.001

Percentile

32.6%