CVE-2021-31918
Summary
| CVE | CVE-2021-31918 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-05-06 17:15:00 UTC |
| Updated | 2022-10-25 19:26:00 UTC |
| Description | A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update and creation. The highest threat from this vulnerability is to data confidentiality. |
Risk And Classification
Problem Types: CWE-732
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1954250 – (CVE-2021-31918) CVE-2021-31918 tripleo-ansible: ansible.log file is visible to unprivileged users | MISC | bugzilla.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 239348 Red Hat Update for Red Hat OpenStack Platform 16.1.6 (tripleo-ansible) (RHSA-2021:2119)