A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update and creation. The highest threat from this vulnerability is to data confidentiality.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1954250 | Issue Tracking Vendor Advisory |
Configurations
Information
Published : 2021-05-06 10:15
Updated : 2022-10-25 12:26
NVD link : CVE-2021-31918
Mitre link : CVE-2021-31918
JSON object : View
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
Products Affected
redhat
- openstack