PackStack 2012.2.3 in Red Hat OpenStack Essex and Folsom can create the answer file in insecure directories such as /tmp or the current working directory, which allows local users to modify deployed systems by changing this file.
Weaknesses in this category are related to the management of credentials.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/83017 | vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=917904 | exploit |
http://rhn.redhat.com/errata/RHSA-2013-0671.html | vendor advisory |