puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions.
References
Link | Resource |
---|---|
http://rhn.redhat.com/errata/RHSA-2017-0200.html | Vendor Advisory |
http://rhn.redhat.com/errata/RHSA-2017-0359.html | Vendor Advisory |
http://rhn.redhat.com/errata/RHSA-2017-0361.html | Vendor Advisory |
http://www.securityfocus.com/bid/95448 | Third Party Advisory VDB Entry |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9590 | Issue Tracking Patch Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2018-04-26T17:00:00
Updated: 2018-04-27T09:57:01
Reserved: 2016-11-23T00:00:00
Link: CVE-2016-9590
JSON object: View
NVD Information
Status : Modified
Published: 2018-04-26T17:29:00.230
Modified: 2021-08-04T17:15:35.690
Link: CVE-2016-9590
JSON object: View
Redhat Information
No data.
CWE