CVE-2013-0266

MEDIUM

OpenStack Essex - Information Disclosure via World-Readable Configuration Files

Title source: llm
STIX 2.1

Description

A flaw was found in the `puppetlabs-cinder` module, as used in PackStack. This vulnerability is due to incorrect file permissions, specifically world-readable permissions, on the `cinder.conf` and `api-paste.ini` configuration files. A local user can exploit this by reading these files, which leads to the disclosure of OpenStack administrative passwords. This information disclosure could allow unauthorized access to sensitive OpenStack resources.

Scores

CVSS v3 5.5
EPSS 0.0003
EPSS Percentile 10.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-276 CWE-362
Status published
Products (4)
openstack/essex
openstack/folsom
Red Hat/Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)
Red Hat/Red Hat OpenStack Platform 4
Published Mar 08, 2013
Tracked Since Feb 18, 2026