CVE-2016-9590: Openstack Puppet-Swift

Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.

puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions.

Affected products

  • Openstack Puppet-Swift: from 8.0.0, before 8.2.1 (fixed in 8.2.1); from 9.0.0, before 9.4.4 (fixed in 9.4.4)
  • Red Hat Openstack: version 8 only; version 9 only; version 10 only

Published 2018-04-26. Last modified 2026-06-17.