CVE-2019-3895
published 2019-06-03CVE-2019-3895: An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker could cause…
PriorityP342high8CVSS 3.1
AVNACLPRLUIRSUCHIHAH
EPSS
1.42%
70.1th percentile
An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker could cause new amphorae to run based on any arbitrary image. This meant that a remote attacker could upload a new amphorae image and, if requested to spawn new amphorae, Octavia would then pick up the compromised image.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | octavia | — | — |
| openstack | octavia | < 0.9.0 | 0.9.0 |
| openstack | octavia | >= 0 < 0.9.0 | 0.9.0 |
| red_hat | openstack-tripleo-common | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.18.0HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv3.05.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_debian8.0LOW
vendor_redhat8.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-tripleo-common: Allows running new amphorae based on arbitrary images
vendor_redhat·2019-05-27·CVSS 8.0
CVE-2019-3895 [HIGH] CWE-284 openstack-tripleo-common: Allows running new amphorae based on arbitrary images
openstack-tripleo-common: Allows running new amphorae based on arbitrary images
An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker could cause new amphorae to run based on any arbitrary image. This meant that a remote attacker could upload a new amphorae image and, if requested to spawn new amphorae, Octavia would then pick up the compromised image.
An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker could cause new amphorae to run based on any arbitrary image. This meant that a remote attacker could upload a new amphorae image and, if requested to spawn new amphorae, Octavia would then pick up the
Debian
CVE-2019-3895: octavia - An access-control flaw was found in the Octavia service when the cloud platform ...
vendor_debian·2019·CVSS 8.0
CVE-2019-3895 [HIGH] CVE-2019-3895: octavia - An access-control flaw was found in the Octavia service when the cloud platform ...
An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker could cause new amphorae to run based on any arbitrary image. This meant that a remote attacker could upload a new amphorae image and, if requested to spawn new amphorae, Octavia would then pick up the compromised image.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
Openstack Octavia Access Control Vulnerability
ghsa·2022-05-24
CVE-2019-3895 [MEDIUM] CWE-284 Openstack Octavia Access Control Vulnerability
Openstack Octavia Access Control Vulnerability
### Description
An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker could cause new amphorae to run based on any arbitrary image. This meant that a remote attacker could upload a new amphorae image and, if requested to spawn new amphorae, Octavia would then pick up the compromised image.
### Mitigation
To prevent this vulnerability:
1. Update Octavia's configuration setting (octavia.conf) to `amp_image_owner_id = $UUID_OF_SERVICE_PROJECT` on all Octavia nodes.
2. Enable the new configuration by restarting both `octavia_worker` and `octavia_health_manager`.
OSV
Openstack Octavia Access Control Vulnerability
osv·2022-05-24
CVE-2019-3895 [MEDIUM] Openstack Octavia Access Control Vulnerability
Openstack Octavia Access Control Vulnerability
### Description
An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker could cause new amphorae to run based on any arbitrary image. This meant that a remote attacker could upload a new amphorae image and, if requested to spawn new amphorae, Octavia would then pick up the compromised image.
### Mitigation
To prevent this vulnerability:
1. Update Octavia's configuration setting (octavia.conf) to `amp_image_owner_id = $UUID_OF_SERVICE_PROJECT` on all Octavia nodes.
2. Enable the new configuration by restarting both `octavia_worker` and `octavia_health_manager`.
OSV
CVE-2019-3895: An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director
osv·2019-06-03
CVE-2019-3895 CVE-2019-3895: An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director
An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker could cause new amphorae to run based on any arbitrary image. This meant that a remote attacker could upload a new amphorae image and, if requested to spawn new amphorae, Octavia would then pick up the compromised image.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-3895 openstack-tripleo-common: Allows running new amphorae based on arbitrary images [openstack-rdo]
bugzilla·2019-05-27·CVSS 8.0
CVE-2019-3895 [HIGH] CVE-2019-3895 openstack-tripleo-common: Allows running new amphorae based on arbitrary images [openstack-rdo]
CVE-2019-3895 openstack-tripleo-common: Allows running new amphorae based on arbitrary images [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Fix
Bugzilla
CVE-2019-3895 openstack-tripleo-common: Allows running new amphorae based on arbitrary images
bugzilla·2019-04-01·CVSS 8.0
CVE-2019-3895 [HIGH] CVE-2019-3895 openstack-tripleo-common: Allows running new amphorae based on arbitrary images
CVE-2019-3895 openstack-tripleo-common: Allows running new amphorae based on arbitrary images
An attacker may cause new amphorae to run based on any arbitrary
image. The attacker only needs to create an image in his/her own user
project, set same tag "amphora-image" and share it with the "service"
project. Upon request to spawn new amphorae, Octavia will now pick up
the compromised image.
Discussion:
Acknowledgments:
Name: Carlos Goncalves (Red Hat)
---
Octavia was introduced in Red Hat OpenStack 12 and has been supported in newer versions. Upstream identified the issue and the code was merged into products delivered by Red Hat, however the configuration was not set by default. This CVE covers Red Hat OpenStack Director's default deployment of Octavia being insecure.
Related upstrea
https://access.redhat.com/errata/RHSA-2019:1683https://access.redhat.com/errata/RHSA-2019:1742https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3895https://access.redhat.com/errata/RHSA-2019:1683https://access.redhat.com/errata/RHSA-2019:1742https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3895
2019-06-03
Published