Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-2622

Опубликовано: 27 июл. 2018
Источник: debian

Описание

An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mistralnot-affectedpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1420992

  • tracing the installation shows that mkdir -p /var/log/mistral

  • is executed, which depending on the umask might end in wrong

  • permissions. But for Debian the final permissions seem to end

  • to 0750, despite, owned by mistral:adm. Thus might need more

  • investigation to determine the affected status.

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 7 лет назад

An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.

CVSS3: 5.9
redhat
почти 9 лет назад

An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.

CVSS3: 5.9
nvd
больше 7 лет назад

An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.

CVSS3: 5.5
github
больше 3 лет назад

An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.