Red Hat Bugzilla – Bug 1420992
CVE-2017-2622 openstack-mistral: /var/log/mistral/ is world readable
Last modified: 2017-06-28 19:46:42 EDT
The directory /var/log/mistral is world readable and contains log files that are readable, which can result in the exposure of sensitive information. The 'other readable/execute' bits need to be removed from the /var/log/mistral directory: [stack@instack ~]$ ls -la /var/log/mistral total 2288 drwxr-xr-x. 2 mistral mistral 4096 Feb 9 01:07 . drwxr-xr-x. 31 root root 4096 Feb 9 01:02 .. -rw-r--r--. 1 mistral mistral 112623 Feb 9 20:09 api.log -rw-r--r--. 1 mistral mistral 1829883 Feb 9 20:09 engine.log -rw-r--r--. 1 mistral mistral 383889 Feb 9 20:09 executor.log
Acknowledgments: Name: Hans Feldt (Ericsson)
Created openstack-mistral tracking bugs for this issue: Affects: openstack-rdo [bug 1422267]
This issue has been addressed in the following products: Red Hat OpenStack Platform 10.0 (Newton) Via RHSA-2017:1584 https://access.redhat.com/errata/RHSA-2017:1584