First published: Tue Nov 01 2016(Updated: )
A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitive information. A local, unprivileged user could possibly use this flaw to access unauthorized system information.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Openstack | =10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-2121 is considered a moderate severity vulnerability due to the potential for unauthorized access to sensitive information.
To fix CVE-2016-2121, ensure that Redis is configured to use proper file permissions and consider upgrading to a patched version of the affected software.
CVE-2016-2121 affects users of Red Hat OpenStack 10 where Redis is deployed with weak file permissions.
CVE-2016-2121 impacts systems running Redis within the Red Hat OpenStack 10 environment.
CVE-2016-2121 is primarily a local vulnerability, meaning it requires local access to exploit.