[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Openstack-security] [Bug 1749326] Re: Exploitable services exposed on community test nodes

We preinstall restrictive iptables rulesets on our images when building
them via
config/tree/nodepool/elements/nodepool-base/install.d/20-iptables and
devstack configures keystone's memcached_servers setting to
localhost:11211 so that it traverses the loopback interface rather than
an externally-reachable address.

You received this bug notification because you are a member of OpenStack
Security SIG, which is subscribed to OpenStack.

  Exploitable services exposed on community test nodes

Status in kolla-ansible:

Bug description:
  One of the donor service providers for the upstream OpenStack
  Infrastructure CI pool has notified us that their security team's
  periodic vulnerability scans have been identifying systems at random
  within our environment as running open memcached servers. Job
  correlation from these reports indicates each was running one of the


  Please adjust the configuration of your job framework to prevent these
  services from being exposed to the Internet (through iptables ingress
  filters, service ACLs, configuring them to not listen on globally-
  routable interfaces, whatever works). Thanks!

To manage notifications about this bug go to: