Описание
A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes using thin volumes and zero padding. This could lead to leakage of sensitive information between tenants.
An information-leak flaw was found in openstack-cinder deployments using the third-party EMC ScaleIO backend. It was possible for new volumes to contain previous data if they were created from storage pools which had disabled zero-padding. An attacker could exploit this flaw to obtain sensitive information.
Отчет
With this update, disabled zero-padding is no longer the default for new volumes. Users can override this behavior by setting the new configuration item, "sio_allow_non_padded_volumes=True". However, the default should not be overridden if multiple tenants will be using volumes from a shared Storage Pool.
Меры по смягчению последствий
This flaw only affects Red Hat OpenStack Platform deployments which use the third-party EMC ScaleIO driver plugin. To mitigate this flaw, ensure all volumes use zero-padding by updating the ScaleIO storage-pool policy. Note: Only an empty pool's policy can be changed.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | openstack-cinder | Not affected | ||
| Red Hat Fuse 7 | openstack-cinder | Not affected | ||
| Red Hat JBoss Fuse 6 | openstack-cinder | Not affected | ||
| Red Hat OpenShift Enterprise 3 | cinder | Not affected | ||
| Red Hat OpenStack Platform 12 (Pike) | openstack-cinder | Affected | ||
| Red Hat OpenStack Platform 14 (Rocky) | openstack-cinder | Not affected | ||
| Red Hat OpenStack Platform 8 (Liberty) | openstack-cinder | Will not fix | ||
| Red Hat OpenStack Platform 9 (Mitaka) | openstack-cinder | Affected | ||
| Red Hat Storage 3 | cinder | Not affected | ||
| Red Hat OpenStack Platform 10.0 (Newton) | openstack-cinder | Fixed | RHSA-2019:0917 | 30.04.2019 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.8 Medium
CVSS3
Связанные уязвимости
A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes using thin volumes and zero padding. This could lead to leakage of sensitive information between tenants.
A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes using thin volumes and zero padding. This could lead to leakage of sensitive information between tenants.
A vulnerability was found in openstack-cinder releases up to and inclu ...
A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes using thin volumes and zero padding. This could lead to leakage of sensitive information between tenants.
EPSS
4.8 Medium
CVSS3