An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2621 | issue tracking vendor advisory |
https://access.redhat.com/errata/RHSA-2017:1243 | vendor advisory |
https://access.redhat.com/errata/RHSA-2017:1464 | vendor advisory |
http://www.securityfocus.com/bid/96280 | vdb entry third party advisory broken link |