CVE-2013-0266

A flaw was found in the `puppetlabs-cinder` module, as used in PackStack. This vulnerability is due to incorrect file permissions, specifically world-readable permissions, on the `cinder.conf` and `api-paste.ini` configuration files. A local user can exploit this by reading these files, which leads to the disclosure of OpenStack administrative passwords. This information disclosure could allow unauthorized access to sensitive OpenStack resources.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openstack:essex:-:*:*:*:*:*:*:*
cpe:2.3:a:openstack:folsom:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2013-03-08 21:55

Updated : 2026-06-16 23:49


NVD link : CVE-2013-0266

Mitre link : CVE-2013-0266

CVE.ORG link : CVE-2013-0266


JSON object : View

Products Affected

openstack

  • folsom
  • essex
CWE
CWE-276

Incorrect Default Permissions

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')