GHSA-7x96-2w32-w3gw

Suggest an improvement
Source
https://github.com/advisories/GHSA-7x96-2w32-w3gw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/03/GHSA-7x96-2w32-w3gw/GHSA-7x96-2w32-w3gw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7x96-2w32-w3gw
Aliases
  • CVE-2022-3101
Published
2023-03-23T21:30:19Z
Modified
2023-11-08T04:09:22.413887Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
tripleo-ansible may disclose important configuration details from an OpenStack deployment
Details

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to information disclosure of important configuration details from the OpenStack deployment.

Database specific
{
    "nvd_published_at": "2023-03-23T21:15:00Z",
    "github_reviewed_at": "2023-03-23T23:12:17Z",
    "severity": "MODERATE",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-22",
        "CWE-276",
        "CWE-732"
    ]
}
References

Affected packages

PyPI / tripleo-ansible

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
6.0.0

Affected versions

6.*

6.0.0