-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from an incomplete fix in CVE-2023-1625, which aimed to hide sensitive data via the 'hidden' flag. The stack abandon command's implementation likely involves EngineService.abandon_stack to coordinate abandonment and ResourceAbandonData.serialize to format the output. If either function fails to apply the hidden flag checks universally (e.g., missing nested resources or specific edge cases), sensitive data persists in the response. The confidence is medium due to reliance on Heat's architecture and typical vulnerability patterns, as explicit patch details are unavailable.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| openstack-heat | pip | <= 22.0.1 |
Ongoing coverage of React2Shell