CVE-2024-7319 - CVE House
Back to Database
Status published Medium CVE-2024-7319

Openstack-heat: incomplete fix for cve-2023-1625

Vulnerability Description

An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature set to True and the CVE-2023-1625 fix applied.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-7319

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Red Hat would like to thank lujie for reporting this issue.

Affected Vendor

Affected Software

Red Hat OpenStack Platform 13 (Queens), Red Hat OpenStack Platform 16.1, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.0
Vulnerable Versions:
0

Timeline

Official Publish: August 2nd, 2024
Last Modified: November 20th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Weaknesses (CWE)