CVE-2020-10755
published 2020-06-10CVE-2020-10755: An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versions before…
PriorityP338medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
1.20%
65.0th percentile
An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versions before openstack-cinder 15.2.0 and all openstack-cinder 16.x.x versions before openstack-cinder 16.1.0. When using openstack-cinder with the Dell EMC ScaleIO or VxFlex OS backend storage driver, credentials for the entire backend are exposed in the ``connection_info`` element in all Block Storage v3 Attachments API calls containing that element. This flaw enables an end-user to create a volume, make an API call to show the attachment detail information, and retrieve a username and password that may be used to connect to another user's volume. Additionally, these credentials are valid for the ScaleIO or VxFlex OS Management API, should an attacker discover the Management API endpoint. Source: OpenStack project
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | cinder | < cinder 2:16.1.0-1 (bookworm) | cinder 2:16.1.0-1 (bookworm) |
| debian | python-os-brick | < cinder 2:16.1.0-1 (bookworm) | cinder 2:16.1.0-1 (bookworm) |
| openstack | cinder | >= 0 < 2:16.1.0-1 | 2:16.1.0-1 |
| openstack | cinder | >= 0 < 2:16.1.0-1 | 2:16.1.0-1 |
| openstack | cinder | >= 0 < 2:16.1.0-1 | 2:16.1.0-1 |
| openstack | cinder | >= 0 < 2:16.1.0-1 | 2:16.1.0-1 |
| openstack | cinder | >= 14.0.0 < 14.1.0 | 14.1.0 |
| openstack | cinder | >= 15.0.0 < 15.2.0 | 15.2.0 |
| openstack | cinder | >= 16.0.0 < 16.1.0 | 16.1.0 |
| red_hat | openstack-cinder | — | — |
| red_hat | openstack-cinder | — | — |
| red_hat | openstack-cinder | — | — |
| redhat | openstack-cinder | < 14.1.0 | 14.1.0 |
| redhat | openstack-cinder | >= 15.0.0 < 15.2.0 | 15.2.0 |
| redhat | openstack-cinder | >= 16.0.0 < 16.1.0 | 16.1.0 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Openstack cinder Improper handling of ScaleIO backend credentials
osv·2022-05-24
CVE-2020-10755 [HIGH] Openstack cinder Improper handling of ScaleIO backend credentials
Openstack cinder Improper handling of ScaleIO backend credentials
An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versions before openstack-cinder 15.2.0 and all openstack-cinder 16.x.x versions before openstack-cinder 16.1.0. When using openstack-cinder with the Dell EMC ScaleIO or VxFlex OS backend storage driver, credentials for the entire backend are exposed in the ``connection_info`` element in all Block Storage v3 Attachments API calls containing that element. This flaw enables an end-user to create a volume, make an API call to show the attachment detail information, and retrieve a username and password that may be used to connect to another user's volume. Additionally, these credentials are valid f
GHSA
Openstack cinder Improper handling of ScaleIO backend credentials
ghsa·2022-05-24
CVE-2020-10755 [HIGH] CWE-522 Openstack cinder Improper handling of ScaleIO backend credentials
Openstack cinder Improper handling of ScaleIO backend credentials
An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versions before openstack-cinder 15.2.0 and all openstack-cinder 16.x.x versions before openstack-cinder 16.1.0. When using openstack-cinder with the Dell EMC ScaleIO or VxFlex OS backend storage driver, credentials for the entire backend are exposed in the ``connection_info`` element in all Block Storage v3 Attachments API calls containing that element. This flaw enables an end-user to create a volume, make an API call to show the attachment detail information, and retrieve a username and password that may be used to connect to another user's volume. Additionally, these credentials are valid f
OSV
CVE-2020-10755: An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14
osv·2020-06-10·CVSS 6.5
CVE-2020-10755 [MEDIUM] CVE-2020-10755: An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14
An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versions before openstack-cinder 15.2.0 and all openstack-cinder 16.x.x versions before openstack-cinder 16.1.0. When using openstack-cinder with the Dell EMC ScaleIO or VxFlex OS backend storage driver, credentials for the entire backend are exposed in the ``connection_info`` element in all Block Storage v3 Attachments API calls containing that element. This flaw enables an end-user to create a volume, make an API call to show the attachment detail information, and retrieve a username and password that may be used to connect to another user's volume. Additionally, these credentials are valid for the ScaleIO or VxFlex OS Management API, should an attacker disc
Ubuntu
Cinder and os-brick vulnerability
vendor_ubuntu·2020-07-07
CVE-2020-10755 Cinder and os-brick vulnerability
Title: Cinder and os-brick vulnerability
Summary: Cinder and os-brick could be made to expose sensitive information.
David Hill and Eric Harney discovered that Cinder and os-brick incorrectly
handled ScaleIO backend credentials. An attacker could possibly use this issue to
expose sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openstack-cinder: Improper handling of ScaleIO backend credentials
vendor_redhat·2020-06-03·CVSS 6.5
CVE-2020-10755 [MEDIUM] CWE-522 openstack-cinder: Improper handling of ScaleIO backend credentials
openstack-cinder: Improper handling of ScaleIO backend credentials
An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versions before openstack-cinder 15.2.0 and all openstack-cinder 16.x.x versions before openstack-cinder 16.1.0. When using openstack-cinder with the Dell EMC ScaleIO or VxFlex OS backend storage driver, credentials for the entire backend are exposed in the ``connection_info`` element in all Block Storage v3 Attachments API calls containing that element. This flaw enables an end-user to create a volume, make an API call to show the attachment detail information, and retrieve a username and password that may be used to connect to another user's volume. Additionally, these credentials are valid
Debian
CVE-2020-10755: cinder - An insecure-credentials flaw was found in all openstack-cinder versions before o...
vendor_debian·2020·CVSS 6.5
CVE-2020-10755 [MEDIUM] CVE-2020-10755: cinder - An insecure-credentials flaw was found in all openstack-cinder versions before o...
An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versions before openstack-cinder 15.2.0 and all openstack-cinder 16.x.x versions before openstack-cinder 16.1.0. When using openstack-cinder with the Dell EMC ScaleIO or VxFlex OS backend storage driver, credentials for the entire backend are exposed in the ``connection_info`` element in all Block Storage v3 Attachments API calls containing that element. This flaw enables an end-user to create a volume, make an API call to show the attachment detail information, and retrieve a username and password that may be used to connect to another user's volume. Additionally, these credentials are valid for the ScaleIO or VxFlex OS Management API, should an attacker disc
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-10755 openstack-cinder: Improper handling of ScaleIO backend credentials [openstack-rdo]
bugzilla·2020-06-08·CVSS 6.5
CVE-2020-10755 [MEDIUM] CVE-2020-10755 openstack-cinder: Improper handling of ScaleIO backend credentials [openstack-rdo]
CVE-2020-10755 openstack-cinder: Improper handling of ScaleIO backend credentials [openstack-rdo]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of openstack-rdo.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
This product has
Bugzilla
CVE-2020-10755 openstack-cinder: Improper handling of ScaleIO backend credentials
bugzilla·2020-06-02·CVSS 6.5
CVE-2020-10755 [MEDIUM] CVE-2020-10755 openstack-cinder: Improper handling of ScaleIO backend credentials
CVE-2020-10755 openstack-cinder: Improper handling of ScaleIO backend credentials
Improper handling of ScaleIO backend credentials
When using Cinder with the Dell EMC ScaleIO or VxFlex OS backend storage driver, credentials for the entire backend are exposed in the ``connection_info`` element in all Block Storage v3 Attachments API calls containing that element. This enables an end user to create a volume, make an API call to show the attachment detail information, and retrieve a username and password that may be used to connect to another user's volume. Additionally, these credentials are valid for the ScaleIO or VxFlex OS Management API, should an attacker discover the Management API endpoint. Source: OpenStack project
Upstream bug: https://bugs.launchpad.net/cinder/+bug/1823200
Disc
2020-06-10
Published