CVE-2023-6725 - CVE House
Back to Database
Status published Medium CVE-2023-6725

Tripleo-ansible: bind keys are world readable

Vulnerability Description

An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any container could exploit this flaw to access sensitive information.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-6725

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • This issue was discovered by Michael Johnson (Red Hat).

Affected Vendor

Affected Software

Red Hat OpenStack Platform 17.1 for RHEL 8, Red Hat OpenStack Platform 17.1 for RHEL 9, Red Hat OpenStack Platform 16.1, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1, Red Hat OpenStack Platform 18.0
Vulnerable Versions:
0:14.3.1-17.1.20231103003762.el8ost, 0:3.3.1-17.1.20231101233754.el8ost, 0:14.3.1-17.1.20231103010840.el9ost, 0:3.3.1-17.1.20231101230831.el9ost

Timeline

Official Publish: March 15th, 2024
Last Modified: February 25th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.