Back

HIGH

Instack-undercloud: rsync leaks information to undercloud

Published Sep 20, 2023

Description

An information leak was found in OpenStack's undercloud. This flaw allows unauthenticated, remote attackers to inspect sensitive data after discovering the IP address of the undercloud, possibly leading to compromising private information, including administrator access credentials.

Affected products

Remediation

Vendor solution

The rsync daemon is no longer needed and can be manually disabled by running the following commands on the undercloud:

sudo rm /etc/xinetd.d/rsync /etc/rsyncd.conf sudo systemctl restart xinetd

However, this will be reverted if the undercloud gets updated.

Red Hat statement

Red Hat OpenStack Platform releases other than 13 are not affected by this vulnerability. This is because they use a different architecture, which does not rely on rsync running on the undercloud.

Red Hat mitigation

The rsync daemon is no longer needed and can be manually disabled by running the following commands on the undercloud: sudo rm /etc/xinetd.d/rsync /etc/rsyncd.conf sudo systemctl restart xinetd However, this will be reverted if the undercloud gets updated.

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Sep 20, 2023
Updated Aug 3, 2024
Reserved Oct 18, 2022
CISA Vulnrichment
Updated May 3, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Dec 5, 2022