5.5

CVE-2023-6725

Tripleo-ansible: bind keys are world readable

An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any container could exploit this flaw to access sensitive information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Openstack Platform Version 17.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.101
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-1220 Insufficient Granularity of Access Control

The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.

https://access.redhat.com/errata/RHSA-2024:2736
Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:2770
Vendor Advisory
https://access.redhat.com/security/cve/CVE-2023-6725
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2249273
Vendor Advisory