[openstack-announce] [OSSA 2016-002] Xen connection password leak in logs via StorageError (CVE-2015-8749)

Grant Murphy grant.murphy at hpe.com
Tue Jan 12 18:05:06 UTC 2016


====================================================================
OSSA-2016-002: Xen connection password leak in logs via StorageError
====================================================================

:Date: January 11, 2016
:CVE: CVE-2015-8749


Affects
~~~~~~~
- Nova: >=2014.2 <= 2015.1.2, == 12.0.0


Description
~~~~~~~~~~~
Matt Riedemann from IBM reported an information disclosure
vulnerability in Nova. If a StorageError occurs when attempting to
connect a volume using the Xen API, the connection parameters will be
logged. These parameters may include credentials that are not masked.
An attacker with read access to Nova logs could use these credentials
with the Xen API directly. Only Nova deployments using the Xen backend
are affected by this flaw.


Patches
~~~~~~~
- https://review.openstack.org/249239 (Kilo)
- https://review.openstack.org/247825 (Liberty)
- https://review.openstack.org/245987 (Mitaka)


Credits
~~~~~~~
- Matt Riedemann from IBM (CVE-2015-8749)


References
~~~~~~~~~~
- https://bugs.launchpad.net/bugs/1516765
- http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8749


Notes
~~~~~
- This fix will be included in future 2015.1.3 (kilo) and 12.0.1 (liberty)
  releases.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 473 bytes
Desc: not available
URL: <http://lists.openstack.org/pipermail/openstack-announce/attachments/20160112/67513bc0/attachment.pgp>


More information about the OpenStack-announce mailing list