{"id":"CVE-2016-9590","details":"puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions.","modified":"2026-07-08T05:48:23.051919467Z","published":"2018-04-26T17:29:00.230Z","database_specific":{"unresolved_ranges":[{"source":"CPE_STRING","vendor_product":"redhat:openstack","cpes":["cpe:2.3:a:redhat:openstack:10:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openstack:8:*:*:*:*:*:*:*","cpe:2.3:a:redhat:openstack:9:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"8"},{"last_affected":"8"},{"introduced":"9"},{"last_affected":"9"},{"introduced":"10"},{"last_affected":"10"}]}]},"references":[{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2017-0200.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2017-0359.html"},{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2017-0361.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/95448"},{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-9590"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openstack/puppet-swift","events":[{"introduced":"7f8469a6c8a0dd600c81a5a4697b3e0dc873744d"},{"fixed":"7ed0b70294a07e514fbd12a74a424de0c5bad0f5"},{"introduced":"fbc530a9d3912ccaaa00df463237d1339e88be52"},{"fixed":"f75979a613b1cc745e95498f10c69c4a421f271e"}],"database_specific":{"extracted_events":[{"introduced":"8.0.0"},{"fixed":"8.2.1"},{"introduced":"9.0.0"},{"fixed":"9.4.4"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:openstack:puppet-swift:*:*:*:*:*:*:*:*"}}],"versions":["9.4.3","9.4.2","9.4.1","9.4.0","9.3.0","8.2.0","9.2.0","9.1.0","9.0.0","8.1.0","8.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-9590.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}