CVE-2016-9590: Infoleak
puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9590?
CVE-2016-9590 has a moderate severity rating due to its potential for information disclosure.
How do I fix CVE-2016-9590?
To fix CVE-2016-9590, upgrade Puppet Swift to version 8.2.1 or later, or version 9.4.4 or later.
Which software versions are affected by CVE-2016-9590?
CVE-2016-9590 affects Puppet Swift versions prior to 8.2.1 and 9.4.4, as well as Red Hat OpenStack versions 8, 9, and 10.
What type of vulnerability is CVE-2016-9590?
CVE-2016-9590 is classified as an information disclosure vulnerability.
In which environment is CVE-2016-9590 found?
CVE-2016-9590 is found in the Red Hat OpenStack Platform director's installation of Object Storage (swift).