CVE-2021-31918: Infoleak
A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update and creation. The highest threat from this vulnerability is to data confidentiality.
Other sources
Flaw was found in tripleo-ansible. Ansible log file is accessible to all users during stack update/creation.
#getfacl /var/lib/mistral/overcloud/ansible.log owner: 42430 group: 42430 user::rw- group::r-- other::r-- ========> This is the problem
This was discovered/reported in a related flaw: https://bugzilla.redhat.com/showbug.cgi?id=1936278
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-31918.
What is the severity of CVE-2021-31918?
The severity of CVE-2021-31918 is high.
Which software versions are affected by CVE-2021-31918?
The affected software version is Red Hat Openstack 16.1.
How does CVE-2021-31918 impact data confidentiality?
The highest threat from CVE-2021-31918 is to data confidentiality.
Is there a reference link for more information?
Yes, you can find more information about CVE-2021-31918 [here](https://bugzilla.redhat.com/show_bug.cgi?id=1954250).