Back

HIGH

openstack-cinder: Data retained after deletion of a ScaleIO volume

Published Aug 27, 2018

Description

A vulnerability was found in openstack-cinder releases up to and including Queens, allowing newly created volumes in certain storage volume configurations to contain previous data. It specifically affects ScaleIO volumes using thin volumes and zero padding. This could lead to leakage of sensitive information between tenants.

Affected products

Remediation

Red Hat statement

With this update, disabled zero-padding is no longer the default for new volumes. Users can override this behavior by setting the new configuration item, "sio_allow_non_padded_volumes=True". However, the default should not be overridden if multiple tenants will be using volumes from a shared Storage Pool.

Red Hat mitigation

This flaw only affects Red Hat OpenStack Platform deployments which use the third-party EMC ScaleIO driver plugin. To mitigate this flaw, ensure all volumes use zero-padding by updating the ScaleIO storage-pool policy. Note: Only an empty pool's policy can be changed. ~~~ scli --modify_zero_padding_policy (((--protection_domain_id <ID> | --protection_domain_name <NAME>) --storage_pool_name <NAME>) | --storage_pool_id <ID>) (--enable_zero_padding | --disable_zero_padding) Example: scli --modify_zero_padding_policy --protection_domain_name pd10 --storage_pool_name scale1 --enable_zero_padding ~~~

Metrics

References (8)

Change history (4)
  1. MITRE
    • CVSS vector changed from CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N to CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
    • CVSS score changed from 4.8 to 5.1
  2. REDHAT
    • CVSS vector changed from CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N to CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N
    • CVSS score changed from 5.1 to 4.8
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 27, 2018
Updated Aug 5, 2024
Reserved Oct 8, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 10, 2018