Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-16856

Опубликовано: 26 мар. 2019
Источник: nvd
CVSS3: 5.5
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openstack:octavia:*:*:*:*:*:*:*:*
Версия от 2.0.0 (включая) до 2.0.2-5 (исключая)
cpe:2.3:a:openstack:octavia:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.0.1-0.20181009115732 (исключая)
Конфигурация 2

Одно из

cpe:2.3:a:redhat:openstack:12:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:14:*:*:*:*:*:*:*

EPSS

Процентиль: 50%
0.00267
Низкий

5.5 Medium

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-532
CWE-532

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 7 лет назад

In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.

CVSS3: 5.5
redhat
больше 7 лет назад

In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.

CVSS3: 5.5
debian
почти 7 лет назад

In a default Red Hat Openstack Platform Director installation, opensta ...

CVSS3: 7.5
github
больше 3 лет назад

Openstack Octavia allows Insertion of Sensitive Information into Log File

EPSS

Процентиль: 50%
0.00267
Низкий

5.5 Medium

CVSS3

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-532
CWE-532