CVE-2021-31918

HIGH

Redhat Openstack - Information Disclosure

Title source: rule
STIX 2.1

Description

A flaw was found in tripleo-ansible version as shipped in Red Hat Openstack 16.1. The Ansible log file is readable to all users during stack update and creation. The highest threat from this vulnerability is to data confidentiality.

References (1)

Core 1
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1954250

Scores

CVSS v3 7.5
EPSS 0.0021
EPSS Percentile 43.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200 CWE-732
Status published
Products (1)
redhat/openstack 16.1
Published May 06, 2021
Tracked Since Feb 18, 2026