CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
openstack-utils openstack-db has insecure password creation | 7.5 |
High |
||
Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive information such as Puppet log files. | 2.1 |
|||
PackStack 2012.2.3 in Red Hat OpenStack Essex and Folsom can create the answer file in insecure directories such as /tmp or the current working directory, which allows local users to modify deployed systems by changing this file. | 4.4 |