PT-2013-3405 · Red Hat · Red Hat Openstack Packstack

Derek Higgins

+1

·

Published

2013-04-10

·

Updated

2026-04-30

·

CVE-2013-1815

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Red Hat OpenStack PackStack versions 2012.2.3
Description The issue allows local users to modify deployed systems by changing the answer file, which can be created in insecure directories such as /tmp or the current working directory.
Recommendations For PackStack version 2012.2.3, consider restricting access to the answer file to prevent local users from modifying deployed systems. As a temporary workaround, ensure that the answer file is created in a secure directory to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2013-1815
RHSA-2013:0671

Affected Products

Red Hat Openstack Packstack