Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
puppet-tripleo is a key component of the Red Hat OpenStack Platform
director, which is a toolset for installing and managing a complete
OpenStack environment.
Security Fix(es):
* An access-control flaw was discovered in puppet-tripleo's IPtables rules
management, which allowed the creation of TCP/UDP rules with empty port
values. Some API services in Red Hat OpenStack Platform director are not
exposed to public networks, which meant their $public_ssl_port value was
set to empty (for example, openstack-glance, which is deployed by default
on both undercloud and overcloud). If SSL was enabled, a malicious user
could use these open ports to gain access to unauthorized resources.
(CVE-2016-9599)
This issue was discovered by Ben Nemec (Red Hat).
https://access.redhat.com/security/cve/CVE-2016-9599 https://access.redhat.com/security/updates/classification/#important
Red Hat OpenStack Platform 10.0:
Source:
puppet-tripleo-5.4.0-4.el7ost.src.rpm
noarch:
puppet-tripleo-5.4.0-4.el7ost.noarch.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
An update for puppet-tripleo is now available for Red Hat OpenStackPlatform 10.0 (Newton).Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.
Red Hat OpenStack Platform 10.0 - noarch
1409687 - CVE-2016-9599 puppet-tripleo:if ssl is enabled, traffic is open on both undercloud and overcloud
Get the latest Linux and open source security news straight to your inbox.