CVE-2022-3146
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
23/03/2023
Last modified:
07/11/2023
Description
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to information disclosure of important configuration details from the OpenStack deployment.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:openstack:tripleo_ansible:-:*:*:*:*:*:*:* | ||
cpe:2.3:a:redhat:openstack:16.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:redhat:openstack:16.2:-:*:*:*:*:*:* | ||
cpe:2.3:a:redhat:openstack_for_ibm_power:16.1:*:*:*:*:*:*:* | ||
cpe:2.3:a:redhat:openstack_for_ibm_power:16.2:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page