CVE-2018-16856
published 2019-03-26CVE-2018-16856: In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and…
PriorityP337high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
0.88%
55.3th percentile
In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | octavia | — | — |
| openstack | octavia | >= 0 < 2.0.3 | 2.0.3 |
| openstack | octavia | >= 0 < 2.1.0 | 2.1.0 |
| openstack | octavia | >= 2.0.0 < 2.0.2-5 | 2.0.2-5 |
| openstack | octavia | >= 3.0.0 < 3.0.1-0.20181009115732 | 3.0.1-0.20181009115732 |
| openstack | octavia | >= 3.0.0 < 3.0.2 | 3.0.2 |
| openstack | octavia | >= 3.0.0.0b1 < 3.1.0 | 3.1.0 |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-octavia: Private keys written to world-readable log files
vendor_redhat·2018-09-26·CVSS 5.5
CVE-2018-16856 [MEDIUM] CWE-532 openstack-octavia: Private keys written to world-readable log files
openstack-octavia: Private keys written to world-readable log files
In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.
In a default Red Hat Openstack Platform Director installation, openstack-octavia creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.
Package: openstack-octavia (Red Hat OpenStack Platform 12 (Pike)) - Will not fix
Debian
CVE-2018-16856: octavia - In a default Red Hat Openstack Platform Director installation, openstack-octavia...
vendor_debian·2018·CVSS 5.5
CVE-2018-16856 [MEDIUM] CVE-2018-16856: octavia - In a default Red Hat Openstack Platform Director installation, openstack-octavia...
In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
Openstack Octavia allows Insertion of Sensitive Information into Log File
ghsa·2022-05-13
CVE-2018-16856 [HIGH] CWE-532 Openstack Octavia allows Insertion of Sensitive Information into Log File
Openstack Octavia allows Insertion of Sensitive Information into Log File
In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.
OSV
Openstack Octavia allows Insertion of Sensitive Information into Log File
osv·2022-05-13
CVE-2018-16856 [HIGH] Openstack Octavia allows Insertion of Sensitive Information into Log File
Openstack Octavia allows Insertion of Sensitive Information into Log File
In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.
OSV
CVE-2018-16856: In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2
osv·2019-03-26
CVE-2018-16856 CVE-2018-16856: In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2
In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-16856 openstack-octavia: Private keys written to world-readable log files
bugzilla·2018-11-13·CVSS 5.5
CVE-2018-16856 [MEDIUM] CVE-2018-16856 openstack-octavia: Private keys written to world-readable log files
CVE-2018-16856 openstack-octavia: Private keys written to world-readable log files
In a default Openstack Director installation, openstack-octavia creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.
Discussion:
Created openstack-octavia tracking bugs for this issue:
Affects: openstack-rdo [bug 1649166]
---
This issue has been addressed in the following products:
Red Hat OpenStack Platform 13.0 (Queens)
Via RHSA-2019:0567 https://access.redhat.com/errata/RHSA-2019:0567
---
This issue has been addressed in the following products:
Red Hat OpenStack Platform 14.0 (Rocky)
Via RHSA-2019:0593 https://access.redhat.com/errata/RHSA-2019:0593
---
Acknowledgments:
Name: Garth Molle
Bugzilla
CVE-2018-16856 openstack-octavia: Private keys written to world-readable log files [openstack-rdo]
bugzilla·2018-11-13·CVSS 5.5
CVE-2018-16856 [MEDIUM] CVE-2018-16856 openstack-octavia: Private keys written to world-readable log files [openstack-rdo]
CVE-2018-16856 openstack-octavia: Private keys written to world-readable log files [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2018-16856 openstack-octavia: Private keys written to world-readable log files [openstack-14-default]
bugzilla·2018-09-26·CVSS 5.5
CVE-2018-16856 [MEDIUM] CVE-2018-16856 openstack-octavia: Private keys written to world-readable log files [openstack-14-default]
CVE-2018-16856 openstack-octavia: Private keys written to world-readable log files [openstack-14-default]
Created attachment 1487003
log image with server_pem
Description of problem:
In a default Director installation with Octavia:
* On the controller, Octavia logs are world readable, where /var/log/containers/octavia and /var/log/containers/httpd/octavia-api are both 755 and the logs themselves are 644.
* The /var/log/containers/octavia/worker.log has private key data (see attachment).
Version-Release number of selected component (if applicable):
How reproducible:
The octavia.yaml file was not modified in the deployment:
openstack overcloud deploy --templates -e /home/stack/templates/node-info.yaml -e /usr/share/openstack-tripleo-heat-templates/environments/services-docker/octavia.ya
2019-03-26
Published