First published: Tue May 21 2013(Updated: )
OpenStack devstack uses world-readable permissions for keystone.conf, which allows local users to obtain sensitive information such as the LDAP password and admin_token secret by reading the file.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenStack DevStack |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-1977 is classified as a medium severity vulnerability due to the exposure of sensitive information.
To fix CVE-2013-1977, change the file permissions of keystone.conf to restrict access for non-privileged users.
CVE-2013-1977 allows local users to access sensitive information such as the LDAP password and admin_token secret from keystone.conf.
CVE-2013-1977 affects OpenStack devstack.
CVE-2013-1977 is not remotely exploitable as it requires local access to the file with world-readable permissions.