Candidate: CVE-2016-9590 PublicDate: 2018-04-26 17:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9590 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9590 Description: puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851293 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N [6.5 MEDIUM] Patches_puppet-module-swift: upstream_puppet-module-swift: needs-triage precise_puppet-module-swift: DNE precise/esm_puppet-module-swift: DNE trusty_puppet-module-swift: DNE trusty/esm_puppet-module-swift: DNE vivid/stable-phone-overlay_puppet-module-swift: DNE vivid/ubuntu-core_puppet-module-swift: DNE xenial_puppet-module-swift: ignored (end of standard support, was needed) yakkety_puppet-module-swift: ignored (reached end-of-life) zesty_puppet-module-swift: ignored (reached end-of-life) artful_puppet-module-swift: ignored (reached end-of-life) bionic_puppet-module-swift: released (9.4.4-1) cosmic_puppet-module-swift: not-affected (9.4.4-1) disco_puppet-module-swift: not-affected (9.4.4-1) eoan_puppet-module-swift: not-affected (9.4.4-1) focal_puppet-module-swift: not-affected (9.4.4-1) groovy_puppet-module-swift: not-affected (9.4.4-1) hirsute_puppet-module-swift: not-affected (9.4.4-1) impish_puppet-module-swift: not-affected (9.4.4-1) jammy_puppet-module-swift: not-affected (9.4.4-1) devel_puppet-module-swift: not-affected (9.4.4-1)