Junglewise Threat Intelligence

CVE-2024-7319: PYSEC-2026-1750 - openstack-heat may disclose sensitive information

CVE-2024-7319 · Severity: low · CVSS 3.1 · Published 2026-07-07

Technologies: openstack-heat (PyPI). Vendors: OpenStack, PyPI.

Executive brief

OpenStack Heat is an orchestration service that manages cloud infrastructure as code in OpenStack deployments. A flaw in the stack abandon command can leak sensitive information such as passwords when the hidden feature is enabled. This could allow authenticated administrators to view credentials that should remain protected, potentially compromising guest virtual machines or gaining unauthorized access to infrastructure components.

Technical details

An incomplete fix for CVE-2023-1625 was found in OpenStack Heat, classified as a CWE-200 exposure of sensitive information vulnerability. The flaw exists in the stack abandon command when the hidden feature is set to True, allowing sensitive data (passwords) to be disclosed to authenticated users. The attack requires network access and low privileges (an authenticated user with stack management capabilities), with no user interaction needed. An attacker can exploit this to retrieve sensitive information that would normally be hidden. Red Hat rates this as CVSS v3.1 score 5.0 (Medium) with vector AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N. Patches are expected to be available through upstream OpenStack and Red Hat channels.

Affected products

  • OpenStack Heat through 22.0.1

Timeline

  • 2024-08-02: disclosed
  • 2024-08-05: other: GitHub reviewed

References

Related threats