Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7x96-2w32-w3gw

Опубликовано: 23 мар. 2023
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

tripleo-ansible may disclose important configuration details from an OpenStack deployment

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to information disclosure of important configuration details from the OpenStack deployment.

Пакеты

Наименование

tripleo-ansible

pip
Затронутые версииВерсия исправления

<= 6.0.0

Отсутствует

EPSS

Процентиль: 2%
0.00015
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-22
CWE-276
CWE-732

Связанные уязвимости

CVSS3: 7.3
redhat
больше 3 лет назад

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to information disclosure of important configuration details from the OpenStack deployment.

CVSS3: 5.5
nvd
почти 3 года назад

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to information disclosure of important configuration details from the OpenStack deployment.

EPSS

Процентиль: 2%
0.00015
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-22
CWE-276
CWE-732