CVE-2013-0266: Puppetlabs-cinder: packstack: openstack: puppetlabs-cinder: information disclosure of openstack administrative passwords due to world-readable configuration files.

Published Feb 7, 2013
·
Updated

A flaw was found in the puppetlabs-cinder module, as used in PackStack. This vulnerability is due to incorrect file permissions, specifically world-readable permissions, on the cinder.conf and api-paste.ini configuration files. A local user can exploit this by reading these files, which leads to the disclosure of OpenStack administrative passwords. This information disclosure could allow unauthorized access to sensitive OpenStack resources.

Other sources

Derek Higgins (derekh) reports:

puppetlabs-cinder / manifests / base.pp as used in OpenStack packstack uses unsafe file permissions (mode 0644) for various config files (cinder.conf and api-paste.ini) which can result in authorization credentials being exposed to local attackers.

External references: https://github.com/puppetlabs/puppetlabs-cinder/blob/master/manifests/base.pp#L31 mode => '0644',

Red Hat

manifests/base.pp in the puppetlabs-cinder module, as used in PackStack, uses world-readable permissions for the (1) cinder.conf and (2) api-paste.ini configuration files, which allows local users to read OpenStack administrative passwords by reading the files.

Affected Software

2 affected components
Openstack Essex
Openstack folsom

Event History

Feb 7, 2013
Data Sourced
via Red Hat·04:37 AM
DescriptionSeverityAffected Software
Mar 8, 2013
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:55 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2013-0266?

CVE-2013-0266 has a medium severity due to potential exposure of sensitive configuration files.

2

How do I fix CVE-2013-0266?

To fix CVE-2013-0266, ensure that the file permissions for cinder.conf and api-paste.ini are set to a more restrictive mode, such as 0600.

3

Which versions of OpenStack are affected by CVE-2013-0266?

CVE-2013-0266 affects OpenStack Essex and Folsom.

4

What files are vulnerable in CVE-2013-0266?

The vulnerable files in CVE-2013-0266 are cinder.conf and api-paste.ini.

5

Who reported CVE-2013-0266?

CVE-2013-0266 was reported by Derek Higgins.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203