Cinder throws detailed iSCSI information in case of failure
Bug #1644554 reported by
Adam Heczko
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Cinder |
New
|
Undecided
|
Unassigned | ||
OpenStack Compute (nova) |
Incomplete
|
Undecided
|
Unassigned | ||
OpenStack Security Advisory |
Won't Fix
|
Undecided
|
Unassigned |
Bug Description
Apologies for vague bug report but I think this should be reported anyway:
When for some reason iSCSI attachment fails Cinder (or Nova) throws detailed iSCSI information including cloud internal Cinder volume IP address and volume details.
Observed this while operating on Nova instances with Cinder volumes using Horizon.
OpenStack Liberty or Mitaka.
Such detailed iSCSI message reported to end user through Horizon UI is considered as a security violation.
description: | updated |
To post a comment you must log in.
Since this report concerns a possible security risk, an incomplete security advisory task has been added while the core security reviewers for the affected project or projects confirm the bug and discuss the scope of any vulnerability along with potential solutions.
What are the information leaked with the volume details? Can you please provide an example error message with the relevant log detail to help us diagnose this issue?