Openstack Octavia allows Insertion of Sensitive Information into Log File
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Oct 7, 2024
Description
Published by the National Vulnerability Database
Mar 26, 2019
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Apr 29, 2024
Last updated
Oct 7, 2024
In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.
References