tripleo-ansible: /var/lib/mistral/overcloud discoverable
Published Mar 23, 2023
7.3
HIGHCVSS 3.1
EPSS 0.20%
Description
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to information disclosure of important configuration details from the OpenStack deployment.
Affected products
- Vendor n/a Product Tripleo-Ansible Defaultunknown
Affected
- unknown
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Tripleo-Ansible | unknown | Affected
|
- n/a
- 16.1
- 16.2
- 16.1
- 16.2
No data.
Red Hat OpenStack Platform 16.1
openstack-tripleo-common-0:11.4.1-1.20211201113404.el8ost
Fixed · RHSA-2022:6969
Red Hat OpenStack Platform 16.1
tripleo-ansible-0:0.5.1-1.20220114163454.el8ost
Fixed · RHSA-2022:6969
Red Hat OpenStack Platform 16.2
openstack-tripleo-common-0:11.7.1-2.20220318011206.el8ost
Fixed · RHSA-2022:6969
Red Hat OpenStack Platform 16.2
tripleo-ansible-0:0.8.1-2.20220406160116.el8ost
Fixed · RHSA-2022:6969
Red Hat OpenStack Platform 13 (Queens)
tripleo-ansible
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 16.1 | openstack-tripleo-common-0:11.4.1-1.20211201113404.el8ost | Fixed | RHSA-2022:6969 |
| Red Hat OpenStack Platform 16.1 | tripleo-ansible-0:0.5.1-1.20220114163454.el8ost | Fixed | RHSA-2022:6969 |
| Red Hat OpenStack Platform 16.2 | openstack-tripleo-common-0:11.7.1-2.20220318011206.el8ost | Fixed | RHSA-2022:6969 |
| Red Hat OpenStack Platform 16.2 | tripleo-ansible-0:0.8.1-2.20220406160116.el8ost | Fixed | RHSA-2022:6969 |
| Red Hat OpenStack Platform 13 (Queens) | tripleo-ansible | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://access.redhat.com/security/cve/CVE-2022-3101 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2123870 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-0934 Advisory
- https://github.com/advisories/GHSA-7x96-2w32-w3gw Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3101
- https://www.cve.org/CVERecord?id=CVE-2022-3101
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub