The log-viewing function in the Red Hat redhat-access-plugin before 6.0.3 for OpenStack Dashboard (horizon) allows remote attackers to read arbitrary files via a crafted path.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://rhn.redhat.com/errata/RHSA-2015-0841.html | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2015-0645.html | vendor advisory |
http://rhn.redhat.com/errata/RHSA-2015-0840.html | vendor advisory |