Medium severity5.5NVD Advisory· Published Mar 15, 2024· Updated Jun 17, 2026
CVE-2023-6725
CVE-2023-6725
Description
An access-control flaw was found in the OpenStack Designate component where private configuration information including access keys to BIND were improperly made world readable. A malicious attacker with access to any container could exploit this flaw to access sensitive information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:/a:redhat:openstack:16.1+ 6 more
- cpe:/a:redhat:openstack:16.1
- cpe:/a:redhat:openstack:16.2
- cpe:/a:redhat:openstack:17.1
- cpe:/a:redhat:openstack:17.1::el8range: 0:3.3.1-17.1.20231101233754.el8ost
- cpe:/a:redhat:openstack:17.1::el9range: 0:3.3.1-17.1.20231101230831.el9ost
- cpe:/a:redhat:openstack:18.0
- cpe:2.3:a:redhat:openstack_platform:17.1:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- access.redhat.com/errata/RHSA-2024:2736nvdVendor Advisory
- access.redhat.com/errata/RHSA-2024:2770nvdVendor Advisory
- access.redhat.com/security/cve/CVE-2023-6725nvdVendor Advisory
- bugzilla.redhat.com/show_bug.cginvdVendor Advisory
News mentions
0No linked articles in our index yet.