« Volver al listado

CVE-2023-6725

Estado: ModificadaMedia (5.5)—

An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any container could exploit this flaw to access sensitive information.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-6725",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-6725",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-03-15T16:37:30.842696Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secalert@redhat.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      },
      {
        "type": "Secondary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:/a:redhat:openstack:17.1::el8"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenStack Platform 17.1 for RHEL 8",
          "versions": [
            {
              "status": "unaffected",
              "version": "0:14.3.1-17.1.20231103003762.el8ost",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "openstack-tripleo-heat-templates",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openstack:17.1::el8"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenStack Platform 17.1 for RHEL 8",
          "versions": [
            {
              "status": "unaffected",
              "version": "0:3.3.1-17.1.20231101233754.el8ost",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "tripleo-ansible",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openstack:17.1::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenStack Platform 17.1 for RHEL 9",
          "versions": [
            {
              "status": "unaffected",
              "version": "0:14.3.1-17.1.20231103010840.el9ost",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "openstack-tripleo-heat-templates",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openstack:17.1::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenStack Platform 17.1 for RHEL 9",
          "versions": [
            {
              "status": "unaffected",
              "version": "0:3.3.1-17.1.20231101230831.el9ost",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "tripleo-ansible",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openstack:16.1"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenStack Platform 16.1",
          "packageName": "openstack-designate",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openstack:16.2"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenStack Platform 16.2",
          "packageName": "openstack-designate",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openstack:17.1"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenStack Platform 17.1",
          "packageName": "openstack-designate",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:openstack:18.0"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat OpenStack Platform 18.0",
          "packageName": "openstack-designate",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-03-15T13:15:06.857",
  "references": [
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:2736",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:2770",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2023-6725",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2249273",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:2736",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:2770",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2023-6725",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2249273",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1220"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any container could exploit this flaw to access sensitive information."
    },
    {
      "lang": "es",
      "value": "Se encontró una falla de control de acceso en el componente OpenStack Designate donde la información de configuración privada, incluidas las claves de acceso a BIND, no se hizo legible en todo el mundo de manera incorrecta. Un atacante malicioso con acceso a cualquier contenedor podría aprovechar esta falla para acceder a información confidencial."
    }
  ],
  "lastModified": "2026-06-17T06:51:18.430",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:redhat:openstack_platform:17.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E315FC5C-FF19-43C9-A58A-CF2A5FF13824"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}