First published: Thu Dec 08 2022(Updated: )
Installation tools to install an undercloud via instack<br>Security Fix(es):<br><li> instack-undercloud: rsync leaks information to undercloud (CVE-2022-3596)</li> For more details about the security issue(s), including the impact, a CVSS<br>score, acknowledgments, and other related information, refer to the CVE<br>page listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/instack-undercloud | <8.4.9-13.el7 | 8.4.9-13.el7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of RHSA-2022:8897 is classified as important.
To fix RHSA-2022:8897, update the instack-undercloud package to version 8.4.9-13.el7 or later.
RHSA-2022:8897 addresses the vulnerability CVE-2022-3596 where rsync leaks information to the undercloud.
The affected package for RHSA-2022:8897 is instack-undercloud.
RHSA-2022:8897 provides a security fix for information leakage via rsync related to CVE-2022-3596.