Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-3146

Опубликовано: 02 сент. 2022
Источник: redhat
CVSS3: 7.3

Описание

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to information disclosure of important configuration details from the OpenStack deployment.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 13 (Queens)tripleo-ansibleNot affected
Red Hat OpenStack Platform 16.1tripleo-ansibleFixedRHSA-2022:696917.10.2022
Red Hat OpenStack Platform 16.2tripleo-ansibleFixedRHSA-2022:696917.10.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22->CWE-276->CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=2124721tripleo-ansible: /etc/openstack/clouds.yaml discoverable

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
почти 3 года назад

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to information disclosure of important configuration details from the OpenStack deployment.

CVSS3: 5.5
github
почти 3 года назад

tripleo-ansible may disclose important configuration details from an OpenStack deployment

7.3 High

CVSS3