CVE-2023-6725
Tripleo-ansible: bind keys are world readable
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any container could exploit this flaw to access sensitive information.
Se encontró una falla de control de acceso en el componente OpenStack Designate donde la información de configuración privada, incluidas las claves de acceso a BIND, no se hizo legible en todo el mundo de manera incorrecta. Un atacante malicioso con acceso a cualquier contenedor podría aprovechar esta falla para acceder a información confidencial.
An update for openstack-tripleo-heat-templates and tripleo-ansible is now available for Red Hat OpenStack Platform 17.1 for RHEL 9.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2023-12-12 CVE Reserved
- 2024-03-15 CVE Published
- 2024-11-24 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-1220: Insufficient Granularity of Access Control
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2024:2736 | 2024-05-22 | |
https://access.redhat.com/errata/RHSA-2024:2770 | 2024-05-22 | |
https://access.redhat.com/security/cve/CVE-2023-6725 | 2024-05-22 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2249273 | 2024-05-22 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Openstack Search vendor "Redhat" for product "Openstack" | * | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | * | - |
Affected
|