{"api_version":"1","generated_at":"2026-07-24T01:40:08+00:00","cve":"CVE-2021-31918","urls":{"html":"https://cve.report/CVE-2021-31918","api":"https://cve.report/api/cve/CVE-2021-31918.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-31918","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-31918"},"summary":{"title":"CVE-2021-31918","description":"A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update and creation. The highest threat from this vulnerability is to data confidentiality.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2021-05-06 17:15:00","updated_at":"2022-10-25 19:26:00"},"problem_types":["CWE-732"],"metrics":[],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1954250","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1954250","refsource":"MISC","tags":[],"title":"1954250 – (CVE-2021-31918) CVE-2021-31918 tripleo-ansible: ansible.log file is visible to unprivileged users","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-31918","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-31918","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"31918","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redhat","cpe5":"openstack","cpe6":"16.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-31918","qid":"239348","title":"Red Hat Update for Red Hat OpenStack Platform 16.1.6 (tripleo-ansible) (RHSA-2021:2119)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2021-31918","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"tripleo-ansible","version":{"version_data":[{"version_value":"As shipped in Red Hat Openstack 16.1"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-200"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1954250","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1954250"}]},"description":{"description_data":[{"lang":"eng","value":"A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update and creation. The highest threat from this vulnerability is to data confidentiality."}]}},"nvd":{"publishedDate":"2021-05-06 17:15:00","lastModifiedDate":"2022-10-25 19:26:00","problem_types":["CWE-732"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:redhat:openstack:16.1:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"31918","Ordinal":"207235","Title":"CVE-2021-31918","CVE":"CVE-2021-31918","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"31918","Ordinal":"1","NoteData":"A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update and creation. The highest threat from this vulnerability is to data confidentiality.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"31918","Ordinal":"2","NoteData":"2021-05-06","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"31918","Ordinal":"3","NoteData":"2021-05-06","Type":"Other","Title":"Modified"}]}}}