PackStack中使用的puppetlabs-cinder模块中的manifests/base.pp中存在存在漏洞,该漏洞源于(1)cinder.conf和(2)api-paste.ini配置文件使用全局可读权限。通过读取文件,本地攻击者利用该漏洞读取OpenStack管理员密码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse) | any |
affected |
| Red Hat | Red Hat OpenStack Platform 4 | any |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse) | - |
cpe:/a:redhat:openstack:5::el6
|
|
| Red Hat | Red Hat OpenStack Platform 4 | - |
cpe:/a:redhat:openstack:4
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet