CVE-2018-16856: Openstack Octavia

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

In a default Red Hat Openstack Platform Director installation, openstack-octavia before versions openstack-octavia 2.0.2-5 and openstack-octavia-3.0.1-0.20181009115732 creates log files that are readable by all users. Sensitive information such as private keys can appear in these log files allowing for information exposure.

Affected products

  • Openstack Octavia: from 2.0.0, before 2.0.2-5 (fixed in 2.0.2-5); from 3.0.0, before 3.0.1-0.20181009115732 (fixed in 3.0.1-0.20181009115732)
  • Red Hat Openstack: version 12 only; version 13 only; version 14 only

Published 2019-03-26. Last modified 2026-06-17.