CVE-2013-1977
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
21/05/2013
Last modified:
11/04/2025
Description
OpenStack devstack uses world-readable permissions for keystone.conf, which allows local users to obtain sensitive information such as the LDAP password and admin_token secret by reading the file.
Impact
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:openstack:devstack:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.openwall.com/lists/oss-security/2013/04/19/2
- http://www.openwall.com/lists/oss-security/2013/04/23/7
- https://bugs.launchpad.net/devstack/+bug/1168252
- http://www.openwall.com/lists/oss-security/2013/04/19/2
- http://www.openwall.com/lists/oss-security/2013/04/23/7
- https://bugs.launchpad.net/devstack/+bug/1168252