World-readable permissions on cinder.conf and api-paste.ini configuration files in puppetlabs-cinder module allow local users to access OpenStack administrative passwords

World-readable permissions on cinder.conf and api-paste.ini configuration files in puppetlabs-cinder module allow local users to access OpenStack administrative passwords

CVE-2013-0266 · LOW Severity

AV:L/AC:L/AU:N/C:P/I:N/A:N

manifests/base.pp in the puppetlabs-cinder module, as used in PackStack, uses world-readable permissions for the (1) cinder.conf and (2) api-paste.ini configuration files, which allows local users to read OpenStack administrative passwords by reading the files.

Learn more about our Api Penetration Testing.