Bug 961145 (CVE-2015-8749) - VUL-0: CVE-2015-8749 openstack-nova: Xen connection password leak in logs via StorageError
Summary: VUL-0: CVE-2015-8749 openstack-nova: Xen connection password leak in logs via...
Status: RESOLVED WONTFIX
Alias: CVE-2015-8749
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Cloud Bugs
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/160424/
Whiteboard: CVSSv2:SUSE:CVE-2015-8749:3.5:(AV:N/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2016-01-08 12:11 UTC by Johannes Segitz
Modified: 2020-07-26 22:02 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Johannes Segitz 2016-01-08 12:11:20 UTC
rh#1296837

Reporter: Matt Riedemann (IBM)
Products: Nova
Affects: >= 2014.2 <= 2015.1.2, ==12.0.0

Description:

Matt Riedemann from IBM reported an information disclosure vulnerability
in Nova. If a StorageError occurs when attempting to connect a volume
using the Xen API, the connection parameters will be logged. These
parameters may include credentials that are not masked. An attacker
with read access to Nova logs could use these credentials with the
Xen API directly. Only Nova deployments using the Xen backend are
affected by this flaw.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1296837
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8749
http://seclists.org/oss-sec/2016/q1/43
https://bugs.launchpad.net/bugs/1321785
Comment 2 Swamp Workflow Management 2016-01-08 23:00:35 UTC
bugbot adjusting priority
Comment 3 Bernhard Wiedemann 2016-01-25 13:15:14 UTC
In SUSE-Cloud we support Xen via libvirt
which is different from how most people use Xen in OpenStack,
which is why it is not working so well and most of our users use KVM instead.

upstream fix was https://review.openstack.org/#/c/233151/
and I checked that our Cloud6 oslo.versionedobjects-0.10.0
does not contain it atm
Comment 4 Vincent Untz 2016-02-08 16:47:18 UTC
The correct bug for the CVE is https://bugs.launchpad.net/nova/+bug/1516765

This is about xenapi, which is not what we support. We support libvirt+xen.

So doesn't impact us. Security team: is WONTFIX fine?
Comment 5 Sebastian Krahmer 2016-02-09 12:16:18 UTC
If it does not affect us, yes please close.
Comment 6 Vincent Untz 2016-02-09 13:04:06 UTC
As discussed, closing.