Vulnerabilities > CVE-2017-2622 - Files or Directories Accessible to External Parties vulnerability in Redhat Openstack 10

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
local
low complexity
redhat
CWE-552

Summary

An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.

Vulnerable Configurations

Part Description Count
Application
Redhat
1

Redhat

advisories
rhsa
idRHSA-2017:1584
rpms
  • openstack-mistral-all-0:3.0.2-11.el7ost
  • openstack-mistral-api-0:3.0.2-11.el7ost
  • openstack-mistral-common-0:3.0.2-11.el7ost
  • openstack-mistral-engine-0:3.0.2-11.el7ost
  • openstack-mistral-executor-0:3.0.2-11.el7ost
  • python-mistral-tests-0:3.0.2-11.el7ost
  • python-openstack-mistral-0:3.0.2-11.el7ost