← Back

CVE-2022-3101

nvd nist
Published: Mar 23, 2023Modified: Nov 21, 2024

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to information disclosure of important configuration details from the OpenStack deployment.

Affected (5)

1 product
Tripleo Ansible
2 products
Openstack
Openstack For Ibm Power
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Redhat
Version 16.1
Version 16.2
Redhat
Version 16.1
Version 16.2

References (2)

Source: secalert@redhat.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.