A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to information disclosure of important configuration details from the OpenStack deployment.
{ "nvd_published_at": "2023-03-23T21:15:00Z", "github_reviewed_at": "2023-03-23T23:11:40Z", "severity": "MODERATE", "github_reviewed": true, "cwe_ids": [ "CWE-22", "CWE-276", "CWE-732" ] }