Instack-undercloud: rsync leaks information to undercloud
Published Sep 20, 2023
7.5
HIGHCVSS 3.1
EPSS 1.11%
Description
An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect sensitive data after discovering the IP address of the undercloud, possibly leading to compromising private information, including administrator access credentials.
Affected products
No data.
- 13.0
- 13.0
No data.
Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS
instack-undercloud-0:8.4.9-13.el7ost
Fixed · RHSA-2022:8897
Red Hat OpenStack Platform 13.0 - ELS
instack-undercloud-0:8.4.9-13.el7ost
Fixed · RHSA-2022:8897
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 13.0 (Queens) for RHEL 7.6 EUS | instack-undercloud-0:8.4.9-13.el7ost | Fixed | RHSA-2022:8897 |
| Red Hat OpenStack Platform 13.0 - ELS | instack-undercloud-0:8.4.9-13.el7ost | Fixed | RHSA-2022:8897 |
No package ranges for this CVE.
Remediation
Vendor solution
The rsync daemon is no longer needed and can be manually disabled by running the following commands on the undercloud:
sudo rm /etc/xinetd.d/rsync /etc/rsyncd.conf sudo systemctl restart xinetd
However, this will be reverted if the undercloud gets updated.
Red Hat statement
Red Hat OpenStack Platform releases other than 13 are not affected by this vulnerability. This is because they use a different architecture, which does not rely on rsync running on the undercloud.
Red Hat mitigation
The rsync daemon is no longer needed and can be manually disabled by running the following commands on the undercloud: sudo rm /etc/xinetd.d/rsync /etc/rsyncd.conf sudo systemctl restart xinetd However, this will be reverted if the undercloud gets updated.
References (5)
- https://access.redhat.com/errata/RHSA-2022:8897 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2022-3596 vdb-entryx_refsource_REDHATMitigationVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2136596 issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3596
- https://www.cve.org/CVERecord?id=CVE-2022-3596
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2022:8897 | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2022-3596 | vdb-entryx_refsource_REDHATMitigationVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2136596 | issue-trackingx_refsource_REDHATIssue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-3596 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-3596 |
Change history (0)
No recorded changes yet.