CVE-2013-1977

Openstack Devstack - Access Control

Title source: rule

Description

OpenStack devstack uses world-readable permissions for keystone.conf, which allows local users to obtain sensitive information such as the LDAP password and admin_token secret by reading the file.

Scores

EPSS 0.0011
EPSS Percentile 29.9%

Classification

CWE
CWE-264
Status draft

Affected Products (1)

openstack/devstack

Timeline

Published May 21, 2013
Tracked Since Feb 18, 2026