PyPi: Tripleo-Ansible

CVE-2023-6725

Transitive

Safety vulnerability ID: 66950

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Mar 15, 2024 Updated at Nov 29, 2024
Scan your Python projects for vulnerabilities →

Advisory

Tripleo-ansible is affected by CVE-2023-6725: An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any container could exploit this flaw to access sensitive information.

Affected package

tripleo-ansible

Latest version: 6.0.0

Ansible assets for the TripleO project.

Affected versions

Fixed versions

Vulnerability changelog

An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any container could exploit this flaw to access sensitive information. See CVE-2023-6725.


MISC:RHBZ#2249273: https://bugzilla.redhat.com/show_bug.cgi?id=2249273
MISC:https://access.redhat.com/security/cve/CVE-2023-6725: https://access.redhat.com/security/cve/CVE-2023-6725

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application