VYPR
Medium severity5.5GHSA Advisory· Published Mar 26, 2019· Updated Jun 17, 2026

CVE-2018-16856

CVE-2018-16856

Description

In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
octaviaPyPI
< 2.1.02.1.0
octaviaPyPI
>= 3.0.0.0b1, < 3.1.03.1.0

Affected products

6
  • OpenStack/OctaviaGHSA2 versions
    >= 3.0.0.0b1, < 3.1.0+ 1 more
    • (no CPE)range: >= 3.0.0.0b1, < 3.1.0
    • cpe:2.3:a:openstack:octavia:*:*:*:*:*:*:*:*range: >=2.0.0,<2.0.2-5
  • Red Hat/Openstack3 versions
    cpe:2.3:a:redhat:openstack:12:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:redhat:openstack:12:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openstack:13:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openstack:14:*:*:*:*:*:*:*
  • ghsa-coords
    Range: < 2.1.0

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.