4
CVSSv2

CVE-2015-0271

Published: 10/03/2015 Updated: 13/02/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

The log-viewing function in the Red Hat redhat-access-plugin prior to 6.0.3 for OpenStack Dashboard (horizon) allows remote malicious users to read arbitrary files via a crafted path.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openstack 5.0

redhat openstack 6.0

Vendor Advisories

It was found that the local log-viewing function of the redhat-access-plugin for OpenStack Dashboard (horizon) did not sanitize user input An authenticated user could use this flaw to read an arbitrary file with the permissions of the web server ...