MEDIUM5.0
PYSEC-2026-1750
openstack-heat may disclose sensitive information
Details
An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature set to True and the CVE-2023-1625 fix applied.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/openstack-heat
Introduced in:
0No fixed version published yet for openstack-heat (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-7319[ADVISORY]
- https://access.redhat.com/security/cve/CVE-2024-7319[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2258810[WEB]
- https://github.com/openstack/heat[PACKAGE]
- https://storyboard.openstack.org/#!/story/2011007[WEB]
- https://pypi.org/project/openstack-heat[PACKAGE]
- https://github.com/advisories/GHSA-2fqr-cx7q-3ph8[ADVISORY]