CVE-2022-3101
published 2023-03-23CVE-2022-3101: A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.20%
10.1th percentile
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to information disclosure of important configuration details from the OpenStack deployment.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack_for_ibm_power | — | — |
| redhat | openstack_for_ibm_power | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
tripleo-ansible: /var/lib/mistral/overcloud discoverable
vendor_redhat·2022-09-02·CVSS 5.5
CVE-2022-3101 [MEDIUM] CWE-22 tripleo-ansible: /var/lib/mistral/overcloud discoverable
tripleo-ansible: /var/lib/mistral/overcloud discoverable
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to information disclosure of important configuration details from the OpenStack deployment.
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to information disclosure of important configuration details from the OpenStack deployment.
Package: tripleo-ansible
OSV
tripleo-ansible may disclose important configuration details from an OpenStack deployment
osv·2023-03-23
CVE-2022-3101 [MEDIUM] tripleo-ansible may disclose important configuration details from an OpenStack deployment
tripleo-ansible may disclose important configuration details from an OpenStack deployment
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to information disclosure of important configuration details from the OpenStack deployment.
GHSA
tripleo-ansible may disclose important configuration details from an OpenStack deployment
ghsa·2023-03-23
CVE-2022-3101 [MEDIUM] CWE-22 tripleo-ansible may disclose important configuration details from an OpenStack deployment
tripleo-ansible may disclose important configuration details from an OpenStack deployment
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to information disclosure of important configuration details from the OpenStack deployment.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-23
Published