libvirt before 2.2 includes Ceph credentials on the qemu command line when using RADOS Block Device (aka RBD), which allows local users to obtain sensitive information via a process listing.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://wiki.openstack.org/wiki/OSSN/OSSN-0079 | third party advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=1245647 | issue tracking third party advisory |
http://rhn.redhat.com/errata/RHSA-2016-2577.html | third party advisory vendor advisory |
https://bugs.launchpad.net/ossn/+bug/1686743 | issue tracking third party advisory |
http://www.openwall.com/lists/oss-security/2017/07/21/3 | third party advisory mailing list |