CVE-2018-16856 describes an information exposure vulnerability in Red Hat Openstack Platform Director installations using openstack-octavia before versions 2.0.2-5 and 3.0.1-0.20181009115732. Log files created by Octavia are world-readable and can contain sensitive data, including private keys. This vulnerability has a CVSS score of 7.5 (HIGH), indicating a high potential for confidentiality impact due to unauthenticated network access with low attack complexity. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.0.2-5CPE matchmatch criteria | cpe:2.3:a:openstack:octavia:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.0.1-0.20181009115732CPE matchmatch criteria | cpe:2.3:a:openstack:octavia:*:*:*:*:*:*:*:* | ||
12CPE matchmatch criteria | cpe:2.3:a:redhat:openstack:12:*:*:*:*:*:*:* | ||
13CPE matchmatch criteria | cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:* | ||
14CPE matchmatch criteria | cpe:2.3:a:redhat:openstack:14:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.