CVE-2016-9590
published 2018-04-26CVE-2016-9590: puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage…
PriorityP432medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
1.15%
63.2th percentile
puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | puppet-module-swift | < puppet-module-swift 9.4.4-1 (bookworm) | puppet-module-swift 9.4.4-1 (bookworm) |
| openstack | puppet-swift | >= 8.0.0 < 8.2.1 | 8.2.1 |
| openstack | puppet-swift | >= 9.0.0 < 9.4.4 | 9.4.4 |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7q5j-cmrw-cmmc: puppet-swift before versions 8
ghsa_unreviewed·2022-05-13
CVE-2016-9590 [MEDIUM] CWE-200 GHSA-7q5j-cmrw-cmmc: puppet-swift before versions 8
puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions.
OSV
CVE-2016-9590: puppet-swift before versions 8
osv·2018-04-26·CVSS 6.5
CVE-2016-9590 [MEDIUM] CVE-2016-9590: puppet-swift before versions 8
puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions.
Red Hat
puppet-swift: installs config file with world readable permissions
vendor_redhat·2017-01-12·CVSS 6.5
CVE-2016-9590 [MEDIUM] CWE-200 puppet-swift: installs config file with world readable permissions
puppet-swift: installs config file with world readable permissions
puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions.
An information-disclosure flaw was discovered in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions.
Package: openstack-puppet-modules (Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)) - Not
Debian
CVE-2016-9590: puppet-module-swift - puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclo...
vendor_debian·2016·CVSS 6.5
CVE-2016-9590 [MEDIUM] CVE-2016-9590: puppet-module-swift - puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclo...
puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions.
Scope: local
bookworm: resolved (fixed in 9.4.4-1)
bullseye: resolved (fixed in 9.4.4-1)
forky: resolved (fixed in 9.4.4-1)
sid: resolved (fixed in 9.4.4-1)
trixie: resolved (fixed in 9.4.4-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9590 puppet-swift: installs config file with world readable permissions [openstack-rdo]
bugzilla·2017-01-12·CVSS 6.5
CVE-2016-9590 [MEDIUM] CVE-2016-9590 puppet-swift: installs config file with world readable permissions [openstack-rdo]
CVE-2016-9590 puppet-swift: installs config file with world readable permissions [openstack-rdo]
This as an RDO Project security tracking bug against puppet-swift. It was created
to ensure that one or more security vulnerabilities are fixed.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
[bug automatically created by: add-tracking-bugs]
Discussion:
All affected products updated so closing.
Bugzilla
CVE-2016-9590 puppet-swift: installs config file with world readable permissions
bugzilla·2017-01-05·CVSS 6.5
CVE-2016-9590 [MEDIUM] CVE-2016-9590 puppet-swift: installs config file with world readable permissions
CVE-2016-9590 puppet-swift: installs config file with world readable permissions
The openstack-swift package itself installs the file with the correct permissions, however a puppet script that runs as part of the install incorrectly removes and recreates the file with world-readable permissions.
Discussion:
Acknowledgments:
Name: Hans Feldt (Ericsson)
---
Created attachment 1240008
CVE-2016-9590 patch for puppet-swift
---
It should be noted that openstack-11 is not affected as upstream landed a change[0] in how these configuration files are updated. That being said, OSP8,OSP9 are affected via openstack-puppet-modules[1][2]. OSP7 should not be affected as it still had the permissions[3]
[0] https://review.openstack.org/#/c/378950/
[1] https://github.com/redhat-openstack/openstack-p
http://rhn.redhat.com/errata/RHSA-2017-0200.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0359.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0361.htmlhttp://www.securityfocus.com/bid/95448https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9590http://rhn.redhat.com/errata/RHSA-2017-0200.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0359.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0361.htmlhttp://www.securityfocus.com/bid/95448https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9590
2018-04-26
Published