OpenStack Keystone CVE-2012-5483 Insecure File Permissions Vulnerability
BID:56888
Info
OpenStack Keystone CVE-2012-5483 Insecure File Permissions Vulnerability
| Bugtraq ID: | 56888 |
| Class: | Design Error |
| CVE: |
CVE-2012-5483 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 11 2012 12:00AM |
| Updated: | Apr 13 2015 10:00PM |
| Credit: | Kurt Seifried of the Red Hat Security Response Team |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
OpenStack Keystone CVE-2012-5483 Insecure File Permissions Vulnerability
Keystone is prone to an insecure file-permission vulnerability.
A local attacker can exploit this issue to obtain potentially sensitive information, such as a secret key, that may aid in further attacks.
Keystone is prone to an insecure file-permission vulnerability.
A local attacker can exploit this issue to obtain potentially sensitive information, such as a secret key, that may aid in further attacks.
Solution / Fix
OpenStack Keystone CVE-2012-5483 Insecure File Permissions Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
OpenStack Keystone CVE-2012-5483 Insecure File Permissions Vulnerability
References:
References: