An accessibility flaw was found in the OpenStack Workflow (mistral) service where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.
The product makes files or directories accessible to unauthorized actors, even though they should not be.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2622 | issue tracking vendor advisory |
https://access.redhat.com/errata/RHSA-2017:1584 | vendor advisory |