Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-2621

Опубликовано: 27 июл. 2018
Источник: nvd
CVSS3: 5.9
CVSS3: 5.5
CVSS2: 2.1
EPSS Низкий

Описание

An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openstack:heat:*:*:*:*:*:*:*:*
Версия до 8.0.0 (исключая)
cpe:2.3:a:redhat:openstack:9:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*

EPSS

Процентиль: 22%
0.00072
Низкий

5.9 Medium

CVSS3

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-552
CWE-532

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.

CVSS3: 5.9
redhat
почти 9 лет назад

An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.

CVSS3: 5.5
debian
больше 7 лет назад

An access-control flaw was found in the OpenStack Orchestration (heat) ...

CVSS3: 5.5
github
почти 4 года назад

An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.

EPSS

Процентиль: 22%
0.00072
Низкий

5.9 Medium

CVSS3

5.5 Medium

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-552
CWE-532