puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions.
{
"unresolved_ranges": [
{
"source": "CPE_STRING",
"cpes": [
"cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:openstack:8:*:*:*:*:*:*:*",
"cpe:2.3:a:redhat:openstack:9:*:*:*:*:*:*:*"
],
"vendor_product": "redhat:openstack",
"extracted_events": [
{
"introduced": "8"
},
{
"last_affected": "8"
},
{
"introduced": "9"
},
{
"last_affected": "9"
},
{
"introduced": "10"
},
{
"last_affected": "10"
}
]
}
]
}