Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-9590

Опубликовано: 26 апр. 2018
Источник: nvd
CVSS3: 6.5
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openstack:puppet-swift:*:*:*:*:*:*:*:*
Версия от 8.0.0 (включая) до 8.2.1 (исключая)
cpe:2.3:a:openstack:puppet-swift:*:*:*:*:*:*:*:*
Версия от 9.0.0 (включая) до 9.4.4 (исключая)
Конфигурация 2

Одно из

cpe:2.3:a:redhat:openstack:8:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:9:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*

EPSS

Процентиль: 51%
0.00281
Низкий

6.5 Medium

CVSS3

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200
CWE-200

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 8 лет назад

puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions.

CVSS3: 6.5
redhat
около 9 лет назад

puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions.

CVSS3: 6.5
debian
почти 8 лет назад

puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an informat ...

CVSS3: 6.5
github
больше 3 лет назад

puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions.

EPSS

Процентиль: 51%
0.00281
Низкий

6.5 Medium

CVSS3

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-200
CWE-200