Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-16856

Опубликовано: 26 сент. 2018
Источник: redhat
CVSS3: 5.5

Описание

In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.

In a default Red Hat Openstack Platform Director installation, openstack-octavia creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 12 (Pike)openstack-octaviaWill not fix
Red Hat OpenStack Platform 13.0 (Queens)openstack-octaviaFixedRHSA-2019:056714.03.2019
Red Hat OpenStack Platform 14.0 (Rocky)openstack-octaviaFixedRHSA-2019:059318.03.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-532
https://bugzilla.redhat.com/show_bug.cgi?id=1649165openstack-octavia: Private keys written to world-readable log files

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
почти 7 лет назад

In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.

CVSS3: 5.5
nvd
почти 7 лет назад

In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.

CVSS3: 5.5
debian
почти 7 лет назад

In a default Red Hat Openstack Platform Director installation, opensta ...

CVSS3: 7.5
github
больше 3 лет назад

Openstack Octavia allows Insertion of Sensitive Information into Log File

5.5 Medium

CVSS3