Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w4x6-6w3r-9h2m

Опубликовано: 23 мар. 2023
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

tripleo-ansible may disclose important configuration details from an OpenStack deployment

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to information disclosure of important configuration details from the OpenStack deployment.

Пакеты

Наименование

tripleo-ansible

pip
Затронутые версииВерсия исправления

<= 6.0.0

Отсутствует

EPSS

Процентиль: 2%
0.00015
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-22
CWE-276
CWE-732

Связанные уязвимости

CVSS3: 7.3
redhat
больше 3 лет назад

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to information disclosure of important configuration details from the OpenStack deployment.

CVSS3: 5.5
nvd
почти 3 года назад

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to information disclosure of important configuration details from the OpenStack deployment.

EPSS

Процентиль: 2%
0.00015
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-22
CWE-276
CWE-732