Lucene search

K
redhatRedHatRHSA-2022:6969
HistoryOct 17, 2022 - 10:15 a.m.

(RHSA-2022:6969) Important: Red Hat OpenStack Platform (tripleo-ansible) security update

2022-10-1710:15:43
access.redhat.com
24
red hat openstack platform
tripleo ansible
security update
/var/lib/mistral/overcloud
/etc/openstack/clouds.yaml
cve-2022-3101
cve-2022-3146
unix

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

15.9%

TripleO Ansible project repository. Contains playbooks for use with TripleO
OpenStack deployments. https://opendev.org

Security Fix(es):

  • /var/lib/mistral/overcloud discoverable (CVE-2022-3101)

  • /etc/openstack/clouds.yaml discoverable (CVE-2022-3146)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page listed in the References section.

Rows per page:
1-10 of 141

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

15.9%