CVE Vulnerabilities

CVE-2019-3895

Published: Jun 03, 2019 | Modified: Aug 04, 2021
CVSS 3.x
8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
5.5 MODERATE
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Ubuntu
MEDIUM

An access-control flaw was found in the Octavia service when the cloud platform was deployed using Red Hat OpenStack Platform Director. An attacker could cause new amphorae to run based on any arbitrary image. This meant that a remote attacker could upload a new amphorae image and, if requested to spawn new amphorae, Octavia would then pick up the compromised image.

Affected Software

Name Vendor Start Version End Version
Octavia Openstack * 0.9.0 (excluding)
Red Hat OpenStack Platform 13.0 (Queens) RedHat openstack-tripleo-common-0:8.6.8-11.el7ost *
Red Hat OpenStack Platform 14.0 (Rocky) RedHat openstack-tripleo-common-0:9.5.0-5.el7ost *
Octavia Ubuntu cosmic *
Octavia Ubuntu disco *
Octavia Ubuntu eoan *
Octavia Ubuntu groovy *
Octavia Ubuntu hirsute *
Octavia Ubuntu impish *
Octavia Ubuntu kinetic *
Octavia Ubuntu lunar *
Octavia Ubuntu mantic *
Octavia Ubuntu trusty *

References