PT-2023-13042 · Unknown · Tripleo-Ansible

Maciej Relewicz

·

Published

2023-03-23

·

Updated

2023-03-30

·

CVE-2022-3146

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions tripleo-ansible (affected versions not specified)
Description A flaw in the default configuration of tripleo-ansible causes insufficient restriction of permissions for a sensitive file. This allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to information disclosure of important OpenStack deployment configuration details.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Incorrect Default Permissions

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-3146
GHSA-W4X6-6W3R-9H2M
RHSA-2022:6969

Affected Products

Tripleo-Ansible