Title: Xen connection password leak in logs via StorageError Reporter: Matt Riedemann (IBM) Products: Nova Affects: >= 2014.2 <= 2015.1.2, ==12.0.0 Description: Matt Riedemann from IBM reported an information disclosure vulnerability in Nova. If a StorageError occurs when attempting to connect a volume using the Xen API, the connection parameters will be logged. These parameters may include credentials that are not masked. An attacker with read access to Nova logs could use these credentials with the Xen API directly. Only Nova deployments using the Xen backend are affected by this flaw. References: https://launchpad.net/bugs/1516765 http://seclists.org/oss-sec/2016/q1/42
Created openstack-nova tracking bugs for this issue: Affects: fedora-all [bug 1296839]
Statement: Red Hat Enterprise Linux OpenStack Platform does not support the Xen hypervisor, and is therefore not affected by this flaw in any supported configuration.