-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stemmed from insecure file permissions on ceph.client.openstack.keyring. The commits a18fd59 and ce7b65f explicitly show fixes to 'mode' parameters in Heat templates (e.g., changing 0644 to 0600) and adding ACLs. The affected YAML files managed Ceph keyring deployment, and their pre-patch configurations allowed world-readable access. These template sections directly controlled the vulnerable resource permissions.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| tripleo-heat-templates | pip | < 7.0.6 | 7.0.6 |
Ongoing coverage of React2Shell