CVE-2016-9590

MEDIUM

puppet-swift < 8.2.1 - Sensitive Information Exposure via World-Readable Configuration File

Title source: llm
STIX 2.1

Description

puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions.

References (5)

Core 5
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2017-0359.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/95448
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2017-0361.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2017-0200.html
Issue Tracking, Patch, Vendor Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9590

Scores

CVSS v3 6.5
EPSS 0.0028
EPSS Percentile 51.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (4)
openstack/puppet-swift 8.0.0 - 8.2.1
redhat/openstack 8
redhat/openstack 9
redhat/openstack 10
Published Apr 26, 2018
Tracked Since Feb 18, 2026