PT-2021-19593 · Red Hat · Tripleo-Ansible
Pedro Sampaio
·
Published
2021-05-06
·
Updated
2022-10-25
·
CVE-2021-31918
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
tripleo-ansible version as shipped in Red Hat Openstack 16.1
Description:
A flaw was found in the software, where the Ansible log file is readable to all users during stack update and creation. The highest threat from this vulnerability is to data confidentiality.
Recommendations:
For tripleo-ansible version as shipped in Red Hat Openstack 16.1, consider restricting access to the Ansible log file to minimize the risk of exploitation.
Fix
Information Disclosure
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tripleo-Ansible