CVE-2013-1977: Low severity openstack devstack vulnerability
Published May 21, 2013
·Updated
OpenStack devstack uses world-readable permissions for keystone.conf, which allows local users to obtain sensitive information such as the LDAP password and admintoken secret by reading the file.
Affected Software
1 affected component
Openstack devstack
Event History
May 21, 2013
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-1977?
CVE-2013-1977 is classified as a medium severity vulnerability due to the exposure of sensitive information.
2
How do I fix CVE-2013-1977?
To fix CVE-2013-1977, change the file permissions of keystone.conf to restrict access for non-privileged users.
3
What information can be leaked due to CVE-2013-1977?
CVE-2013-1977 allows local users to access sensitive information such as the LDAP password and admin_token secret from keystone.conf.
4
Which software is affected by CVE-2013-1977?
CVE-2013-1977 affects OpenStack devstack.
5
Is CVE-2013-1977 exploitable remotely?
CVE-2013-1977 is not remotely exploitable as it requires local access to the file with world-readable permissions.