CVE-2018-16856

octavia: Insertion of Sensitive Information into Log File (CVE-2018-16856)

Description

In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.

Metrics

Severity
high
no public PoC known
7.5
Source: nvd-v3
57.1 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
0.9 %
Low — model estimates < 1% exploitation likelihood.
Published
2019-03-26 17:45 UTC
CWE-532

Weakness classes (CWE)

  • CWE-532Base

    Insertion of Sensitive Information into Log File

    The product writes sensitive information to a log file.

    cwe.mitre.org →

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • openstack

    octavia2.0.0 – 2.0.2-5

  • openstack

    octavia3.0.0 – 3.0.1-0.20181009115732

  • redhat

    openstack

References & sources

IDCVE-2018-16856