manifests/base.pp in the puppetlabs-cinder module, as used in PackStack, uses world-readable permissions for the (1) cinder.conf and (2) api-paste.ini configuration files, which allows local users to read OpenStack administrative passwords by reading the files.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
openstack essex - |
||
openstack folsom - |