PYSEC-2017-152

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/instack/PYSEC-2017-152.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2017-152
Aliases
Published
2017-09-21T21:29:00.447Z
Modified
2026-05-21T15:00:14.181231588Z
Severity
  • 6.4 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N CVSS Calculator
Summary
[none]
Details

A flaw was found in instack-undercloud 7.2.0 as packaged in Red Hat OpenStack Platform Pike, 6.1.0 as packaged in Red Hat OpenStack Platform Oacta, 5.3.0 as packaged in Red Hat OpenStack Newton, where pre-install and security policy scripts used insecure temporary files. A local user could exploit this flaw to conduct a symbolic-link attack, allowing them to overwrite the contents of arbitrary files.

References

Affected packages

PyPI / instack

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
7.2.0
Last affected
6.1.0
Last affected
5.3.0

Affected versions

0.*
0.0.9.dev4
5.*
5.0.0.0b1
5.0.0.0b2
5.0.0
5.1.0
6.*
6.1.0

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/instack/PYSEC-2017-152.yaml"