CVE-2013-0266

Currently unrated

Key Information:

Vendor
Openstack
Vendor
CVE Published:
8 March 2013

Summary

manifests/base.pp in the puppetlabs-cinder module, as used in PackStack, uses world-readable permissions for the (1) cinder.conf and (2) api-paste.ini configuration files, which allows local users to read OpenStack administrative passwords by reading the files.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.