tripleo-ansible: /etc/openstack/clouds.yaml discoverable
Published Mar 23, 2023
7.3
HIGHCVSS 3.1
EPSS 0.20%
Description
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to information disclosure of important configuration details from the OpenStack deployment.
Affected products
- Vendor n/a Product Tripleo-Ansible Defaultn/a
- Version unkownStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Tripleo-Ansible | n/a |
|
- n/a
- 16.1
- 16.2
- 16.1
- 16.2
No data.
Red Hat OpenStack Platform 16.1
tripleo-ansible-0:0.5.1-1.20220114163454.el8ost
Fixed · RHSA-2022:6969
Red Hat OpenStack Platform 16.2
tripleo-ansible-0:0.8.1-2.20220406160116.el8ost
Fixed · RHSA-2022:6969
Red Hat OpenStack Platform 13 (Queens)
tripleo-ansible
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenStack Platform 16.1 | tripleo-ansible-0:0.5.1-1.20220114163454.el8ost | Fixed | RHSA-2022:6969 |
| Red Hat OpenStack Platform 16.2 | tripleo-ansible-0:0.8.1-2.20220406160116.el8ost | Fixed | RHSA-2022:6969 |
| Red Hat OpenStack Platform 13 (Queens) | tripleo-ansible | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://access.redhat.com/security/cve/CVE-2022-3146 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2124721 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-1127 Advisory
- https://github.com/advisories/GHSA-w4x6-6w3r-9h2m Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-3146
- https://www.cve.org/CVERecord?id=CVE-2022-3146
Change history (0)
No recorded changes yet.