openstack-tripleo-common: Allows running new amphorae based on arbitrary images
Published Jun 3, 2019
5.1
MEDIUMCVSS 4.0
EPSS 1.61%
Description
An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker could cause new amphorae to run based on any arbitrary image. This meant that a remote attacker could upload a new amphorae image and, if requested to spawn new amphorae, Octavia would then pick up the compromised image.
Affected products
-
Affected
- n/a
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Red Hat | Openstack-Tripleo-Common | unknown | Affected
|
No data.
Red Hat OpenStack Platform 13.0 (Queens)
openstack-tripleo-common-0:8.6.8-11.el7ost
Fixed · RHSA-2019:1742
Red Hat OpenStack Platform 14.0 (Rocky)
openstack-tripleo-common-0:9.5.0-5.el7ost
Fixed · RHSA-2019:1683
Red Hat OpenStack Platform 15 (Stein)
openstack-tripleo-common
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 13.0 (Queens) | openstack-tripleo-common-0:8.6.8-11.el7ost | Fixed | RHSA-2019:1742 |
| Red Hat OpenStack Platform 14.0 (Rocky) | openstack-tripleo-common-0:9.5.0-5.el7ost | Fixed | RHSA-2019:1683 |
| Red Hat OpenStack Platform 15 (Stein) | openstack-tripleo-common | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
To prevent this vulnerability: 1. Update Octavia's configuration setting (octavia.conf) to `amp_image_owner_id = $UUID_OF_SERVICE_PROJECT` on all Octavia nodes. 2. Enable the new configuration by restarting both `octavia_worker` and `octavia_health_manager`.
References (16)
- https://access.redhat.com/errata/RHSA-2019:1683 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:1742 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-3895 Vendor Advisory
- https://bugs.launchpad.net/octavia/+bug/1620629
- https://bugs.launchpad.net/tripleo/+bug/1830607
- https://bugzilla.redhat.com/show_bug.cgi?id=1694608 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3895 x_refsource_CONFIRMIssue TrackingMitigationThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-0100 Advisory
- https://github.com/advisories/GHSA-jjgh-m322-fjx6 Advisory
- https://github.com/openstack/octavia/blob/08570831754d9671fbd1756d668f55f191e47ca4/octavia/compute/drivers/nova_driver.py#L35
- https://github.com/openstack/octavia/commit/d7d062a47ab54a540d81f13a0e5f3085ebfaa0d2
- https://github.com/openstack/tripleo-common/commit/e7c5eab712e0f70ecbc6d225d4766e0fe0f3f884
- https://github.com/pypa/advisory-database/tree/main/vulns/octavia/PYSEC-2019-194.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2019-3895
- https://opendev.org/openstack/octavia/commit/d7d062a47ab54a540d81f13a0e5f3085ebfaa0d2
- https://www.cve.org/CVERecord?id=CVE-2019-3895
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub