{"id":"GHSA-qcj3-h27m-mp9x","summary":"Openstack Octavia allows Insertion of Sensitive Information into Log File","details":"In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.","aliases":["CVE-2018-16856","PYSEC-2019-193"],"modified":"2024-10-07T21:35:06.375748Z","published":"2022-05-13T01:07:34Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-04-29T11:08:44Z","nvd_published_at":"2019-03-26T18:29:00Z","cwe_ids":["CWE-532"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-16856"},{"type":"WEB","url":"https://github.com/openstack/octavia/commit/ae7c87f54a6c5483a608d5e9fe51ea1966ea1f7e"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-16856"},{"type":"PACKAGE","url":"https://github.com/openstack/octavia"},{"type":"WEB","url":"https://github.com/openstack/octavia/commits/3.1.0"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/octavia/PYSEC-2019-193.yaml"}],"affected":[{"package":{"name":"octavia","ecosystem":"PyPI","purl":"pkg:pypi/octavia"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.1.0"}]}],"versions":["0.10.0","0.5.2","0.8.0","0.8.1","0.9.0","0.9.1","0.9.2","1.0.0","1.0.0.0b1","1.0.0.0b2","1.0.0.0b3","1.0.0.0rc1","1.0.0.0rc2","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","2.0.0","2.0.0.0b1","2.0.0.0b2","2.0.0.0b3","2.0.0.0rc1","2.0.0.0rc2","2.0.1","2.0.2","2.0.3","2.0.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qcj3-h27m-mp9x/GHSA-qcj3-h27m-mp9x.json"}},{"package":{"name":"octavia","ecosystem":"PyPI","purl":"pkg:pypi/octavia"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0.0b1"},{"fixed":"3.1.0"}]}],"versions":["3.0.0","3.0.0.0b1","3.0.0.0b2","3.0.0.0b3","3.0.0.0rc1","3.0.0.0rc2","3.0.0.0rc3","3.0.1","3.0.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qcj3-h27m-mp9x/GHSA-qcj3-h27m-mp9x.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}