CVE-2017-2622
published 2018-07-27CVE-2017-2622: An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious…
PriorityP423medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.37%
29.3th percentile
An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mistral | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openstack-mistral: /var/log/mistral/ is world readable
vendor_redhat·2017-02-15·CVSS 5.9
CVE-2017-2622 [MEDIUM] CWE-552 openstack-mistral: /var/log/mistral/ is world readable
openstack-mistral: /var/log/mistral/ is world readable
An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.
An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.
Package: openstack-mistral (Red Hat OpenStack Platform 11 (Ocata)) - Not affected
Debian
CVE-2017-2622: mistral - An accessibility flaw was found in the OpenStack Workflow (mistral) service wher...
vendor_debian·2017·CVSS 5.9
CVE-2017-2622 [MEDIUM] CVE-2017-2622: mistral - An accessibility flaw was found in the OpenStack Workflow (mistral) service wher...
An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-6vmp-9x58-mv62: An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable
ghsa_unreviewed·2022-05-13
CVE-2017-2622 [MEDIUM] CWE-200 GHSA-6vmp-9x58-mv62: An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable
An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.
OSV
CVE-2017-2622: An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable
osv·2018-07-27·CVSS 5.5
CVE-2017-2622 [MEDIUM] CVE-2017-2622: An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable
An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-2622 openstack-mistral: /var/log/mistral/ is world readable [openstack-rdo]
bugzilla·2017-02-14·CVSS 5.9
CVE-2017-2622 [MEDIUM] CVE-2017-2622 openstack-mistral: /var/log/mistral/ is world readable [openstack-rdo]
CVE-2017-2622 openstack-mistral: /var/log/mistral/ is world readable [openstack-rdo]
This as an RDO Project security tracking bug against openstack-mistral. It was created
to ensure that one or more security vulnerabilities are fixed.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
[bug automatically created by: add-tracking-bugs]
Discussion:
Fix proposed: https://review.rdoproject.org/r/5251
---
proposed for newton-rdo https://review.rdoproject.org/r/#/c/5614
---
proposed for mitaka-rdo https://review.rdoproject.org/r/#/c/5615
---
proposed backport for ocata-rdo https://review.rdoproject.org/r/5616
---
Copying my comment from (already merged) gerrit review https://review.rdopro
Bugzilla
CVE-2017-2622 openstack-mistral: /var/log/mistral/ is world readable
bugzilla·2017-02-10·CVSS 5.9
CVE-2017-2622 [MEDIUM] CVE-2017-2622 openstack-mistral: /var/log/mistral/ is world readable
CVE-2017-2622 openstack-mistral: /var/log/mistral/ is world readable
The directory /var/log/mistral is world readable and contains log files that are readable, which can result in the exposure of sensitive information. The 'other readable/execute' bits need to be removed from the /var/log/mistral directory:
[stack@instack ~]$ ls -la /var/log/mistral
total 2288
drwxr-xr-x. 2 mistral mistral 4096 Feb 9 01:07 .
drwxr-xr-x. 31 root root 4096 Feb 9 01:02 ..
-rw-r--r--. 1 mistral mistral 112623 Feb 9 20:09 api.log
-rw-r--r--. 1 mistral mistral 1829883 Feb 9 20:09 engine.log
-rw-r--r--. 1 mistral mistral 383889 Feb 9 20:09 executor.log
Discussion:
Acknowledgments:
Name: Hans Feldt (Ericsson)
---
Created openstack-mistral tracking bugs for this issue:
Affects: openstack-rdo [bug 1422267]
2018-07-27
Published