Vulnerability Description
A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update and creation. The highest threat from this vulnerability is to data confidentiality.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Openstack | 16.1 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1954250Issue TrackingVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1954250Issue TrackingVendor Advisory
FAQ
What is CVE-2021-31918?
CVE-2021-31918 is a vulnerability with a CVSS score of 7.5 (HIGH). A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update and creation. The highest threat from this vulnerabi...
How severe is CVE-2021-31918?
CVE-2021-31918 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-31918?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Openstack.