PT-2021-19593 · Red Hat · Tripleo-Ansible

Pedro Sampaio

·

Published

2021-05-06

·

Updated

2022-10-25

·

CVE-2021-31918

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: tripleo-ansible version as shipped in Red Hat Openstack 16.1
Description: A flaw was found in the software, where the Ansible log file is readable to all users during stack update and creation. The highest threat from this vulnerability is to data confidentiality.
Recommendations: For tripleo-ansible version as shipped in Red Hat Openstack 16.1, consider restricting access to the Ansible log file to minimize the risk of exploitation.

Fix

Information Disclosure

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2021-31918
RHSA-2021:2119

Affected Products

Tripleo-Ansible