Safety vulnerability ID: 71382
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Affected versions of the OpenStack Designate package are vulnerable to Information Disclosure due to world-readable RNDC configuration files that expose credentials for controlling BIND. In Red Hat OpenStack Platform 17.1 deployments generated by tripleo-ansible, the /etc/designate and /etc/designate/private directories and files such as /etc/designate/private/bind1.conf are installed with permissive modes, making the RNDC keys readable to any local user within the Designate container.
Latest version: 18.0.0
Heat templates for deploying OpenStack with OpenStack.
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application