CVE-2019-3866: Medium severity red hat openstack mistral vulnerability
A vulnerability was discovered that all the data from the TripleO heat stack (user provided and generated passwords, certificates, ssh keys) are available in the mistral logs on the undercloud, in clear text.
Other sources
An information-exposure vulnerability was discovered where openstack-mistral's undercloud log files containing clear-text information were made world readable. A malicious system user could exploit this flaw to access sensitive user information.
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2019-3866?
CVE-2019-3866 is an information-exposure vulnerability in openstack-mistral.
What is the severity of CVE-2019-3866?
CVE-2019-3866 has a severity score of 5.9 (medium).
How can a malicious system user exploit CVE-2019-3866?
A malicious system user could exploit CVE-2019-3866 by accessing sensitive user information stored in openstack-mistral's undercloud log files.
Which versions of openstack-mistral are affected by CVE-2019-3866?
Versions 7.1.0 up to 9.0.1 of openstack-mistral are affected by CVE-2019-3866.
How can I fix CVE-2019-3866?
To fix CVE-2019-3866, upgrade to version 9.0.2 or later of openstack-mistral.