Bug 1193638 (CVE-2015-0271) - CVE-2015-0271 OpenStack dashboard: log file arbitrary file retrieval
Summary: CVE-2015-0271 OpenStack dashboard: log file arbitrary file retrieval
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2015-0271
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
: 1193491 (view as bug list)
Depends On: 1193739 1193740 1193741
Blocks: 1193492 1193641
TreeView+ depends on / blocked
 
Reported: 2015-02-17 19:13 UTC by Kurt Seifried
Modified: 2023-05-12 21:52 UTC (History)
18 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
It was found that the local log-viewing function of the redhat-access-plugin for OpenStack Dashboard (horizon) did not sanitize user input. An authenticated user could use this flaw to read an arbitrary file with the permissions of the web server.
Clone Of:
Environment:
Last Closed: 2015-04-17 07:40:42 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2015:0645 0 normal SHIPPED_LIVE Important: redhat-access-plugin-openstack security update 2015-03-06 00:28:41 UTC
Red Hat Product Errata RHSA-2015:0840 0 normal SHIPPED_LIVE Important: redhat-access-plugin security update 2015-04-16 17:52:25 UTC
Red Hat Product Errata RHSA-2015:0841 0 normal SHIPPED_LIVE Important: redhat-access-plugin security update 2015-04-16 17:51:55 UTC

Description Kurt Seifried 2015-02-17 19:13:37 UTC
Sara Perez Merino of SensePost reports:

In the file logs/views.py the logs() call fails to sanitize the path taken when
displaying a file requested by a remote client, allowing any readable file on 
the system to be viewed.

Comment 6 Garth Mollett 2015-02-18 03:04:46 UTC
Acknowledgements:

Red Hat would like to thank Sara Perez Merino of SensePost for reporting this issue.

Comment 10 Garth Mollett 2015-02-18 18:54:22 UTC
*** Bug 1193491 has been marked as a duplicate of this bug. ***

Comment 12 errata-xmlrpc 2015-03-05 19:30:22 UTC
This issue has been addressed in the following products:

  OpenStack 6 for RHEL 7

Via RHSA-2015:0645 https://rhn.redhat.com/errata/RHSA-2015-0645.html

Comment 13 errata-xmlrpc 2015-04-16 13:57:18 UTC
This issue has been addressed in the following products:

  OpenStack 5 for RHEL 6

Via RHSA-2015:0841 https://rhn.redhat.com/errata/RHSA-2015-0841.html

Comment 14 errata-xmlrpc 2015-04-16 13:57:57 UTC
This issue has been addressed in the following products:

  OpenStack 5 for RHEL 7

Via RHSA-2015:0840 https://rhn.redhat.com/errata/RHSA-2015-0840.html


Note You need to log in before you can comment on or make changes to this bug.