OSSA-2016-002: Xen connection password leak in logs via StorageError

OSSA-2016-002: Xen connection password leak in logs via StorageError

Date:January 11, 2016
CVE:CVE-2015-8749

Affects

  • Nova: >=2014.2 <= 2015.1.2, == 12.0.0

Description

Matt Riedemann from IBM reported an information disclosure vulnerability in Nova. If a StorageError occurs when attempting to connect a volume using the Xen API, the connection parameters will be logged. These parameters may include credentials that are not masked. An attacker with read access to Nova logs could use these credentials with the Xen API directly. Only Nova deployments using the Xen backend are affected by this flaw.

Credits

  • Matt Riedemann from IBM (CVE-2015-8749)

Notes

  • This fix will be included in future 2015.1.3 (kilo) and 12.0.1 (liberty) releases.
Creative Commons Attribution 3.0 License

Except where otherwise noted, this document is licensed under Creative Commons Attribution 3.0 License. See all OpenStack Legal Documents.