puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions.
2018-04-26T17:29:00.230
2024-11-21T03:01:28.040
Modified
CVSSv3.0: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | openstack | puppet-swift | < 8.2.1 | Yes |
| Application | openstack | puppet-swift | < 9.4.4 | Yes |
| Application | redhat | openstack | 8 | Yes |
| Application | redhat | openstack | 9 | Yes |
| Application | redhat | openstack | 10 | Yes |