Back to search
CVE-2013-1977
Published: May 21, 2013
Modified: Aug 6, 2024
PUBLISHED
Description
OpenStack devstack uses world-readable permissions for keystone.conf, which allows local users to obtain sensitive information such as the LDAP password and admin_token secret by reading the file.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
https://bugs.launchpad.net/devstack/+bug/1168252
x_refsource_MISC
[oss-security] 20130423 Re: CVE-2013-1977 - OpenStack keystone.conf insecure file permissions
mailing-list
x_refsource_MLIST
[oss-security] 20130419 CVE-2013-1977 - OpenStack keystone.conf insecure file permissions
mailing-list
x_refsource_MLIST
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now