World-readable permissions on cinder.conf and api-paste.ini configuration files in puppetlabs-cinder module allow local users to access OpenStack administrative passwords
CVE-2013-0266 · LOW Severity
AV:L/AC:L/AU:N/C:P/I:N/A:N
manifests/base.pp in the puppetlabs-cinder module, as used in PackStack, uses world-readable permissions for the (1) cinder.conf and (2) api-paste.ini configuration files, which allows local users to read OpenStack administrative passwords by reading the files.
Learn more about our Api Penetration Testing.