Security Advisory

CVE-2022-3146

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-03-23 00:00:00
Last updated 2025-02-25 15:41:22
Assigner redhat
State PUBLISHED

Description

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to information disclosure of important configuration details from the OpenStack deployment.