Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive information such as Puppet log files.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Red Hat OpenStack Essex\Folsom 敏感信息漏洞
Vulnerability Description
OpenStack是由Rackspace和NASA共同开发的云计算平台,帮助服务商和企业内部实现类似于Amazon EC2和S3的云基础架构。 Red Hat OpenStack Essex和Folsom中存在漏洞,该漏洞源于程序对所创建的/var/log/puppet目录配置为全局可读权限。本地攻击者可利用该漏洞获得敏感信息如Puppet日志文件。
CVSS Information
N/A
Vulnerability Type
N/A