cbcvebase.
CVE-2016-9590
published 2018-04-26

CVE-2016-9590: puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage…

PriorityP432medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
1.15%
63.2th percentile
puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions.

Affected

6 ranges
VendorProductVersion rangeFixed in
debianpuppet-module-swift< puppet-module-swift 9.4.4-1 (bookworm)puppet-module-swift 9.4.4-1 (bookworm)
openstackpuppet-swift>= 8.0.0 < 8.2.18.2.1
openstackpuppet-swift>= 9.0.0 < 9.4.49.4.4
redhatopenstack
redhatopenstack
redhatopenstack

CVSS provenance

nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.