CVE-2019-14433: Canonical Ubuntu Linux
Medium severity, CVSS 6.5. EPSS: 1.9% chance of exploitation in the next 30 days.
An issue was discovered in OpenStack Nova before 17.0.12, 18.x before 18.2.2, and 19.x before 19.0.2. If an API request from an authenticated user ends in a fault condition due to an external exception, details of the underlying environment may be leaked in the response, and could include sensitive configuration or other data.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only
- Debian Debian Linux: version 10.0 only
- Openstack Nova: before 17.0.12 (fixed in 17.0.12); from 18.0.0, before 18.2.2 (fixed in 18.2.2); from 19.0.0, before 19.0.2 (fixed in 19.0.2)
- Red Hat Openstack: version 10 only; version 13 only; version 14 only
Published 2019-08-09. Last modified 2026-06-17.