CVE-2018-16856
octavia: Insertion of Sensitive Information into Log File (CVE-2018-16856)
highEPSS 0.9%
Description
In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.
Metrics
Severity
high
61.78
no public PoC known
5.5
Published
2019-03-26 17:45 UTC
CWE-532
Weakness classes (CWE)
CWE-532Base
Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.
cwe.mitre.org →
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
openstack
octavia2.0.0 – 2.0.2-5
openstack
octavia3.0.0 – 3.0.1-0.20181009115732
redhat
openstack
References & sources
IDCVE-2018-16856