5.5
CVSSv3

CVE-2017-2621

Published: 27/07/2018 Updated: 12/02/2023
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An access-control flaw was found in the OpenStack Orchestration (heat) service prior to 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat openstack 10

openstack heat

redhat openstack 9

Vendor Advisories

Synopsis Moderate: openstack-heat security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Topic An update for openstack-heat is now available for Red Hat OpenStack Platform 100 (Newton)Red Hat Product Security has rated this update as having a security impact of Moderate A Com ...
Synopsis Moderate: openstack-heat security and bug fix update Type/Severity Security Advisory: Moderate Topic An update for openstack-heat is now available for Red Hat OpenStack Platform 90 (Mitaka)Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerabili ...
An access-control flaw was found in the OpenStack Orchestration (heat) service where a service log directory was improperly made world readable A malicious system user could exploit this flaw to access sensitive information ...