CVE-2022-3146
published 2023-03-23CVE-2022-3146: A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.20%
10.0th percentile
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to information disclosure of important configuration details from the OpenStack deployment.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openstack | — | — |
| redhat | openstack | — | — |
| redhat | openstack_for_ibm_power | — | — |
| redhat | openstack_for_ibm_power | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
tripleo-ansible may disclose important configuration details from an OpenStack deployment
osv·2023-03-23
CVE-2022-3146 [MEDIUM] tripleo-ansible may disclose important configuration details from an OpenStack deployment
tripleo-ansible may disclose important configuration details from an OpenStack deployment
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to information disclosure of important configuration details from the OpenStack deployment.
GHSA
tripleo-ansible may disclose important configuration details from an OpenStack deployment
ghsa·2023-03-23
CVE-2022-3146 [MEDIUM] CWE-22 tripleo-ansible may disclose important configuration details from an OpenStack deployment
tripleo-ansible may disclose important configuration details from an OpenStack deployment
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to information disclosure of important configuration details from the OpenStack deployment.
Red Hat
tripleo-ansible: /etc/openstack/clouds.yaml discoverable
vendor_redhat·2022-09-02·CVSS 5.5
CVE-2022-3146 [MEDIUM] CWE-22 tripleo-ansible: /etc/openstack/clouds.yaml discoverable
tripleo-ansible: /etc/openstack/clouds.yaml discoverable
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to information disclosure of important configuration details from the OpenStack deployment.
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to information disclosure of important configuration details from the OpenStack deployment.
Packag
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-23
Published