Description
In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0099 | In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure. |
Github GHSA |
GHSA-qcj3-h27m-mp9x | Openstack Octavia allows Insertion of Sensitive Information into Log File |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T10:32:54.143Z
Reserved: 2018-09-11T00:00:00.000Z
Link: CVE-2018-16856
No data.
Status : Modified
Published: 2019-03-26T18:29:00.357
Modified: 2024-11-21T03:53:27.430
Link: CVE-2018-16856
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA