David Hill and Eric Harney discovered that Cinder and os-brick incorrectly handled ScaleIO backend credentials. An attacker could possibly use this issue to expose sensitive information.
{ "availability": "No subscription required", "binaries": [ { "binary_version": "2:12.0.9-0ubuntu1.2", "binary_name": "cinder-api" }, { "binary_version": "2:12.0.9-0ubuntu1.2", "binary_name": "cinder-backup" }, { "binary_version": "2:12.0.9-0ubuntu1.2", "binary_name": "cinder-common" }, { "binary_version": "2:12.0.9-0ubuntu1.2", "binary_name": "cinder-scheduler" }, { "binary_version": "2:12.0.9-0ubuntu1.2", "binary_name": "cinder-volume" }, { "binary_version": "2:12.0.9-0ubuntu1.2", "binary_name": "python-cinder" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "2.3.0-0ubuntu1.2", "binary_name": "os-brick-common" }, { "binary_version": "2.3.0-0ubuntu1.2", "binary_name": "python-os-brick" }, { "binary_version": "2.3.0-0ubuntu1.2", "binary_name": "python-os-brick-doc" }, { "binary_version": "2.3.0-0ubuntu1.2", "binary_name": "python3-os-brick" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "2:16.1.0-0ubuntu1", "binary_name": "cinder-api" }, { "binary_version": "2:16.1.0-0ubuntu1", "binary_name": "cinder-backup" }, { "binary_version": "2:16.1.0-0ubuntu1", "binary_name": "cinder-common" }, { "binary_version": "2:16.1.0-0ubuntu1", "binary_name": "cinder-scheduler" }, { "binary_version": "2:16.1.0-0ubuntu1", "binary_name": "cinder-volume" }, { "binary_version": "2:16.1.0-0ubuntu1", "binary_name": "python3-cinder" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "3.0.1-0ubuntu1.2", "binary_name": "os-brick-common" }, { "binary_version": "3.0.1-0ubuntu1.2", "binary_name": "python-os-brick-doc" }, { "binary_version": "3.0.1-0ubuntu1.2", "binary_name": "python3-os-brick" } ] }