2 results (0.004 seconds)

CVSS: 6.4EPSS: 0%CPEs: 1EXPL: 0

OpenStack PackStack 2012.2.1, when the Open vSwitch (OVS) monolithic plug-in is not used, does not properly set the libvirt_vif_driver configuration option when generating the nova.conf configuration, which causes the firewall to be disabled and allows remote attackers to bypass intended access restrictions. OpenStack PackStack 2012.2.1, cuando el plugin monolítico Open vSwitch (OVS) no está utilizado, no establece correctamente la opción de la configuración libvirt_vif_driver cuando genera la configuración nova.conf, lo que causa que se deshabilita el firewall y permite a atacantes remotos evadir las restricciones de acceso. It was discovered that the nova.conf configuration generated by PackStack did not correctly set the libvirt_vif_driver configuration option if the Open vSwitch (OVS) monolithic plug-in was not used. This could result in deployments defaulting to having the firewall disabled unless the nova configuration was manually modified after PackStack was started. • http://rhn.redhat.com/errata/RHSA-2014-1691.html https://access.redhat.com/security/cve/CVE-2014-3703 https://bugzilla.redhat.com/show_bug.cgi?id=1152702 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 4.4EPSS: 0%CPEs: 3EXPL: 1

PackStack 2012.2.3 in Red Hat OpenStack Essex and Folsom can create the answer file in insecure directories such as /tmp or the current working directory, which allows local users to modify deployed systems by changing this file. PackStack 03/02/2012 en Red Hat OpenStack Essex y Folsom se puede crear el archivo de respuesta en los directorios inseguros como /tmp o en el directorio de trabajo actual, que permite a usuarios locales modificar los sistemas desplegados cambiando de este archivo. • http://rhn.redhat.com/errata/RHSA-2013-0671.html https://bugzilla.redhat.com/show_bug.cgi?id=917904 https://exchange.xforce.ibmcloud.com/vulnerabilities/83017 https://access.redhat.com/security/cve/CVE-2013-1815 • CWE-255: Credentials Management Errors •