CVE-2017-7214
Last modified
CVE-2017-7214 is a vulnerability of currently unknown severity. An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notification exception contexts appearing in ERROR level logs may include sensitive information such as account passwords and authorization tokens.. EPSS estimates a 2.28% chance of exploitation in the next 30 days.
Description
An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notification exception contexts appearing in ERROR level logs may include sensitive information such as account passwords and authorization tokens.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openstack | Nova | 13.0.0 |
| Openstack | Nova | 13.1.0 |
| Openstack | Nova | 13.1.1 |
| Openstack | Nova | 13.1.2 |
| Openstack | Nova | 13.1.3 |
| Openstack | Nova | 14.0.0 |
| Openstack | Nova | 14.0.1 |
| Openstack | Nova | 14.0.2 |
| Openstack | Nova | 14.0.3 |
| Openstack | Nova | 14.0.4 |
| Openstack | Nova | 15.0.0 |
| Openstack | Nova | 15.0.1 |
References
- http://www.securityfocus.com/bid/96998Third Party Advisory, VDB Entry
- https://launchpad.net/bugs/1673569Patch, Third Party Advisory
- http://www.securityfocus.com/bid/96998Third Party Advisory, VDB Entry
- https://launchpad.net/bugs/1673569Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-7214?
How severe is CVE-2017-7214?
How do I fix CVE-2017-7214?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-7206The ff_h2645_extract_rbsp function in libavcodec in libav 9.…
- CVE-2017-7207The mem_get_bits_rectangle function in Artifex Software, Inc…
- CVE-2017-7208The decode_residual function in libavcodec in libav 9.21 all…
- CVE-2017-7209The dump_section_as_bytes function in readelf in GNU Binutil…
- CVE-2017-7210objdump in GNU Binutils 2.28 is vulnerable to multiple heap-…
- CVE-2017-7213Zoho ManageEngine Desktop Central before build 100082 allows…
- CVE-2017-7215Cross site scripting in some view elements in the index filt…
- CVE-2017-7216The Management Web Interface in Palo Alto Networks PAN-OS be…
- CVE-2017-7217The Management Web Interface in Palo Alto Networks PAN-OS be…
- CVE-2017-7218The Management Web Interface in Palo Alto Networks PAN-OS be…
- CVE-2017-7219A heap overflow vulnerability in Citrix NetScaler Gateway ve…
- CVE-2017-7220OpenText Documentum Content Server allows superuser access v…
Are you affected by CVE-2017-7214?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
