Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-3866

Опубликовано: 08 нояб. 2019
Источник: debian
EPSS Низкий

Описание

An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world readable. A malicious system user could exploit this flaw to access sensitive user information.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-oslo.utilsfixed3.41.3-1package
python-oslo.utilsfixed3.36.5-0+deb10u1busterpackage
python-oslo.utilsignoredstretchpackage
python-oslo.utilsnot-affectedjessiepackage
python-mistral-libfixed1.2.0-3package
python-mistral-libno-dsabusterpackage
mistralfixed5.1.0-2package
mistralpostponedstretchpackage

Примечания

  • In mistral/5.0.0 the problematic code was moved to the python library.

  • To apply the fixes in mistral or python-mistral-lib, as pre-requisite the

  • python-oslo.utils package needs an update.

  • https://bugzilla.redhat.com/show_bug.cgi?id=1768731

  • https://bugs.launchpad.net/tripleo/+bug/1850843

  • https://opendev.org/openstack/oslo.utils/commit/b41268417cecb12d1d5955ee3107067edf050221

  • Patch for Pike and newer: https://launchpadlibrarian.net/449473654/0001-Ensure-we-mask-sensitive-data-from-Mistral-Action-lo.patch

  • Patch for Pike and newer: https://launchpadlibrarian.net/449472809/0001-Ensure-we-mask-sensitive-data-from-Mistral-Action-lo.patch

EPSS

Процентиль: 29%
0.00105
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 5 лет назад

An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world readable. A malicious system user could exploit this flaw to access sensitive user information.

CVSS3: 5.9
redhat
почти 6 лет назад

An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world readable. A malicious system user could exploit this flaw to access sensitive user information.

CVSS3: 5.5
nvd
больше 5 лет назад

An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world readable. A malicious system user could exploit this flaw to access sensitive user information.

github
около 3 лет назад

An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world readable. A malicious system user could exploit this flaw to access sensitive user information.

CVSS3: 5.9
fstec
почти 6 лет назад

Уязвимость компонента openstack-mistral платформа для построения облачных решений OpenStack Platform, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 29%
0.00105
Низкий