CVE-2022-3596: Instack-undercloud: rsync leaks information to undercloud
An an information leak was discovered in OpenStack's undercloud. Rsync stores sensitive swift data (for example administrative credentials to the overcloud) in a manner that makes this information visible to local users of the undercloud. This enables potentially anyone with network access to the undercloud to further gain access to the rest of an OpenStack deployment.
Other sources
An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect sensitive data after discovering the IP address of the undercloud, possibly leading to compromising private information, including administrator access credentials.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-3596?
CVE-2022-3596 is a vulnerability found in OpenStack's undercloud that allows unauthenticated remote attackers to inspect sensitive data after discovering the IP address of the undercloud.
What is the severity of CVE-2022-3596?
The severity of CVE-2022-3596 is high with a CVSS score of 7.5.
How does CVE-2022-3596 impact Redhat Openstack Platform 13.0?
CVE-2022-3596 affects Redhat Openstack Platform 13.0, allowing unauthenticated remote attackers to inspect sensitive data.
How can CVE-2022-3596 be exploited?
CVE-2022-3596 can be exploited by unauthenticated remote attackers who discover the IP address of the undercloud to access and inspect sensitive data.
Is there a fix available for CVE-2022-3596?
Yes, a fix is available for CVE-2022-3596. Users should apply the appropriate patches provided by Redhat Openstack Platform.