An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any container could exploit this flaw to access sensitive information.
2024-03-15T13:15:06.857
2025-07-30T20:21:05.300
Analyzed
CVSSv3.1: 6.6 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | redhat | openstack_platform | 17.1 | Yes |