Back

HIGH

openstack-tripleo-heat-templates: Ceph client keyring is world-readable when deployed by director

Published Dec 12, 2017

Description

A resource-permission flaw was found in the openstack-tripleo-heat-templates package where ceph.client.openstack.keyring is created as world-readable. A local attacker with access to the key could read or modify data on Ceph cluster pools for OpenStack as though the attacker were the OpenStack service, thus potentially reading or modifying data in an OpenStack Block Storage volume.

Affected products

Remediation

Red Hat mitigation

To mitigate the flaw, use an overcloud post-deploy script[1] to do the following on all overcloud nodes: key=/etc/ceph/ceph.client.openstack.keyring chown root:root $key chmod 600 $key setfacl -m u:glance:r $key setfacl -m u:cinder:r $key setfacl -m u:nova:r $key setfacl -m u: gnocchi:r $key If not using Red Hat OpenStack Platform director, then run the commands above manually on each overcloud node, Warning: Only running 'chmod 600 $key' alone (without an ACL) will prevent OpenStack from reading the key. [1] https://access.redhat.com/documentation/en-us/red_hat_openstack_platform/11/html-single/advanced_overcloud_customization/#sect-Customizing_Overcloud_PostConfiguration_All

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 12, 2017
Updated Sep 16, 2024
Reserved Aug 1, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 19, 2017
GHSA-W8GX-HHCX-PX6W