ZeroHour

CVE-2022-3146

CVSS 3.1
5.5 medium
EPSS
<1%p10
Published
()
Modified
Description

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to information disclosure of important configuration details from the OpenStack deployment.

Vendors
openstackredhat
Products
tripleo ansible, openstack, openstack for ibm power
Weakness
CWE-22, CWE-276, CWE-732
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.