Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qcj3-h27m-mp9x

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Openstack Octavia allows Insertion of Sensitive Information into Log File

In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.

Пакеты

Наименование

octavia

pip
Затронутые версииВерсия исправления

< 2.1.0

2.1.0

Наименование

octavia

pip
Затронутые версииВерсия исправления

>= 3.0.0.0b1, < 3.1.0

3.1.0

EPSS

Процентиль: 50%
0.00267
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 7 лет назад

In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.

CVSS3: 5.5
redhat
больше 7 лет назад

In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.

CVSS3: 5.5
nvd
почти 7 лет назад

In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.

CVSS3: 5.5
debian
почти 7 лет назад

In a default Red Hat Openstack Platform Director installation, opensta ...

EPSS

Процентиль: 50%
0.00267
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-532