CVE-2013-0266 Information
Feb 14, 2021
cve
Description
manifests/base.pp in the puppetlabs-cinder module as used in PackStack uses world-readable permissions for the (1) cinder.conf and (2) api-paste.ini configuration files which allows local users to read OpenStack administrative passwords by reading the files.
Reference
http://rhn.redhat.com/errata/RHSA-2013-0595.html https://bugzilla.redhat.com/show_bug.cgi?id=908581 https://github.com/puppetlabs/puppetlabs-cinder/commit/7da792fbd40c0e6eae1ee093aa00e0b177bd2ebc
Share on: