CVE-2013-0266
MEDIUMOpenStack Essex - Information Disclosure via World-Readable Configuration Files
Title source: llmDescription
A flaw was found in the `puppetlabs-cinder` module, as used in PackStack. This vulnerability is due to incorrect file permissions, specifically world-readable permissions, on the `cinder.conf` and `api-paste.ini` configuration files. A local user can exploit this by reading these files, which leads to the disclosure of OpenStack administrative passwords. This information disclosure could allow unauthorized access to sensitive OpenStack resources.
References (4)
Core 4
Core References
Vendor Advisory
http://rhn.redhat.com/errata/RHSA-2013-0595.html
Vdb Entry, X_Refsource_Redhat vdb-entry
x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2013-0266
Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=908581
Scores
CVSS v3
5.5
EPSS
0.0003
EPSS Percentile
10.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-276
CWE-362
Status
published
Products (4)
openstack/essex
openstack/folsom
Red Hat/Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)
Red Hat/Red Hat OpenStack Platform 4
Published
Mar 08, 2013
Tracked Since
Feb 18, 2026