PT-2023-13042 · Unknown · Tripleo-Ansible

Maciej Relewicz

·

Publicado

2023-03-23

·

Atualizado

2023-03-30

·

CVE-2022-3146

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions tripleo-ansible (affected versions not specified)
Description A flaw in the default configuration of tripleo-ansible causes insufficient restriction of permissions for a sensitive file. This allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to information disclosure of important OpenStack deployment configuration details.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Incorrect Default Permissions

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-3146
GHSA-W4X6-6W3R-9H2M
RHSA-2022:6969

Produtos afetados

Tripleo-Ansible