Bug 1431479
Summary: | openstack-ironic: /var/log/ironic is world readable | |||
---|---|---|---|---|
Product: | Red Hat OpenStack | Reporter: | Summer Long <slong> | |
Component: | openstack-ironic | Assignee: | Dmitry Tantsur <dtantsur> | |
Status: | CLOSED ERRATA | QA Contact: | mlammon | |
Severity: | high | Docs Contact: | ||
Priority: | high | |||
Version: | 10.0 (Newton) | CC: | apevec, bfournie, dtantsur, eglynn, jjoyce, jruzicka, jschluet, lhh, lmartins, lruzicka, mburns, pkilambi, rbartal, rhel-osp-director-maint, srevivo, ssmolyak | |
Target Milestone: | z6 | Keywords: | Security, Triaged, ZStream | |
Target Release: | 10.0 (Newton) | |||
Hardware: | Unspecified | |||
OS: | Unspecified | |||
Whiteboard: | ||||
Fixed In Version: | openstack-ironic-6.2.4-2.el7ost | Doc Type: | If docs needed, set a value | |
Doc Text: |
Originally, the /var/log/ironic was readable to all users. The problem has been fixed. As a result, only the owner and the group members have read access to the directory.
|
Story Points: | --- | |
Clone Of: | 1431468 | |||
: | 1431480 1431483 (view as bug list) | Environment: | ||
Last Closed: | 2017-11-15 13:48:19 UTC | Type: | Bug | |
Regression: | --- | Mount Type: | --- | |
Documentation: | --- | CRM: | ||
Verified Versions: | Category: | --- | ||
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
Cloudforms Team: | --- | Target Upstream Version: | ||
Embargoed: |
Description
Summer Long
2017-03-13 00:46:27 UTC
Derek, mind proposing a backport of https://review.rdoproject.org/r/#/c/5258/ please? It appears that https://review.rdoproject.org/r/#/c/5258/ has merged so moving this to POST. Need to track down whether this is in a z release. installed latest osp10 with puddle 2017-10-30.3 on 11/1/2017 This bug has been verified environment: openstack-ironic-api-6.2.4-2.el7ost.noarch openstack-ironic-conductor-6.2.4-2.el7ost.noarch openstack-ironic-common-6.2.4-2.el7ost.noarch openstack-ironic-inspector-4.2.2-3.el7ost.noarch [stack@undercloud ~]$ sudo ls -la /var/log/ironic total 836 drwxr-x---. 2 ironic ironic 81 Oct 20 17:10 . drwxr-xr-x. 30 root root 4096 Oct 20 17:02 .. -rw-r--r--. 1 ironic ironic 187066 Oct 20 18:33 ironic-api.log -rw-r--r--. 1 ironic ironic 435477 Oct 20 18:34 ironic-conductor.log -rw-r--r--. 1 ironic ironic 0 Oct 20 17:03 ironic-dbsync.log Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2017:3235 |