First published: Tue Mar 26 2019(Updated: )
In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Openstack Octavia | >=2.0.0<2.0.2-5 | |
Openstack Octavia | >=3.0.0<3.0.1-0.20181009115732 | |
Redhat Openstack | =12 | |
Redhat Openstack | =13 | |
Redhat Openstack | =14 | |
pip/octavia | <2.1.0 | 2.1.0 |
pip/octavia | >=3.0.0.0b1<3.1.0 | 3.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.