CVE-2013-0266

A flaw was found in the `puppetlabs-cinder` module, as used in PackStack. This vulnerability is due to incorrect file permissions, specifically world-readable permissions, on the `cinder.conf` and `api-paste.ini` configuration files. A local user can exploit this by reading these files, which leads to the disclosure of OpenStack administrative passwords. This information disclosure could allow unauthorized access to sensitive OpenStack resources.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openstack:essex:-:*:*:*:*:*:*:*
cpe:2.3:a:openstack:folsom:-:*:*:*:*:*:*:*

History

30 Apr 2026, 17:16

Type Values Removed Values Added
CVSS v2 : 2.1
v3 : unknown
v2 : 2.1
v3 : 5.5
References
  • () https://access.redhat.com/security/cve/CVE-2013-0266 -
CWE CWE-276
Summary (en) manifests/base.pp in the puppetlabs-cinder module, as used in PackStack, uses world-readable permissions for the (1) cinder.conf and (2) api-paste.ini configuration files, which allows local users to read OpenStack administrative passwords by reading the files. (en) A flaw was found in the `puppetlabs-cinder` module, as used in PackStack. This vulnerability is due to incorrect file permissions, specifically world-readable permissions, on the `cinder.conf` and `api-paste.ini` configuration files. A local user can exploit this by reading these files, which leads to the disclosure of OpenStack administrative passwords. This information disclosure could allow unauthorized access to sensitive OpenStack resources.

21 Nov 2024, 01:47

Type Values Removed Values Added
References () http://rhn.redhat.com/errata/RHSA-2013-0595.html - Vendor Advisory () http://rhn.redhat.com/errata/RHSA-2013-0595.html - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=908581 - () https://bugzilla.redhat.com/show_bug.cgi?id=908581 -
References () https://github.com/puppetlabs/puppetlabs-cinder/commit/7da792fbd40c0e6eae1ee093aa00e0b177bd2ebc - () https://github.com/puppetlabs/puppetlabs-cinder/commit/7da792fbd40c0e6eae1ee093aa00e0b177bd2ebc -

Information

Published : 2013-03-08 21:55

Updated : 2026-04-30 17:16


NVD link : CVE-2013-0266

Mitre link : CVE-2013-0266

CVE.ORG link : CVE-2013-0266


JSON object : View

Products Affected

openstack

  • folsom
  • essex
CWE
CWE-276

Incorrect Default Permissions

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')