Описание
An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any container could exploit this flaw to access sensitive information.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenStack Platform 16.1 | openstack-designate | Not affected | ||
| Red Hat OpenStack Platform 16.2 | openstack-designate | Not affected | ||
| Red Hat OpenStack Platform 17.1 | openstack-designate | Affected | ||
| Red Hat OpenStack Platform 18.0 | openstack-designate | Not affected | ||
| Red Hat OpenStack Platform 17.1 for RHEL 8 | openstack-tripleo-heat-templates | Fixed | RHSA-2024:2770 | 22.05.2024 |
| Red Hat OpenStack Platform 17.1 for RHEL 8 | tripleo-ansible | Fixed | RHSA-2024:2770 | 22.05.2024 |
| Red Hat OpenStack Platform 17.1 for RHEL 9 | openstack-tripleo-heat-templates | Fixed | RHSA-2024:2736 | 22.05.2024 |
| Red Hat OpenStack Platform 17.1 for RHEL 9 | tripleo-ansible | Fixed | RHSA-2024:2736 | 22.05.2024 |
Показывать по
Дополнительная информация
Статус:
6.6 Medium
CVSS3
Связанные уязвимости
An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any container could exploit this flaw to access sensitive information.
An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any container could exploit this flaw to access sensitive information.
An access-control flaw was found in the OpenStack Designate component ...
An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any container could exploit this flaw to access sensitive information.
Уязвимость службы управления системой доменных имен Designate платформы для построения облачных решений OpenStack Platform, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
6.6 Medium
CVSS3