CVE-2016-9590: Openstack Puppet-Swift
Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.
puppet-swift before versions 8.2.1, 9.4.4 is vulnerable to an information-disclosure in Red Hat OpenStack Platform director's installation of Object Storage (swift). During installation, the Puppet script responsible for deploying the service incorrectly removes and recreates the proxy-server.conf file with world-readable permissions.
Affected products
- Openstack Puppet-Swift: from 8.0.0, before 8.2.1 (fixed in 8.2.1); from 9.0.0, before 9.4.4 (fixed in 9.4.4)
- Red Hat Openstack: version 8 only; version 9 only; version 10 only
Published 2018-04-26. Last modified 2026-06-17.