2.1
CVSSv2

CVE-2013-0266

Published: 08/03/2013 Updated: 18/03/2013
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

manifests/base.pp in the puppetlabs-cinder module, as used in PackStack, uses world-readable permissions for the (1) cinder.conf and (2) api-paste.ini configuration files, which allows local users to read OpenStack administrative passwords by reading the files.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

openstack essex -

openstack folsom -

Vendor Advisories

Synopsis Moderate: openstack-packstack security and bug fix update Type/Severity Security Advisory: Moderate Topic An updated openstack-packstack package that fixes two security issues andseveral bugs is now available for Red Hat OpenStack FolsomThe Red Hat Security Response Team has rated this update as h ...