Vulnerability CVE-2015-3156

Published: 2017-08-11   Modified: 2017-08-25

The _write_config function in trove/guestagent/datastore/experimental/mongodb/, reset_configuration function in trove/guestagent/datastore/experimental/postgresql/service/, write_config function in trove/guestagent/datastore/experimental/redis/, _write_mycnf function in trove/guestagent/datastore/mysql/, InnoBackupEx::_run_prepare function in trove/guestagent/strategies/restore/, InnoBackupEx::cmd function in trove/guestagent/strategies/backup/, MySQLDump::cmd in trove/guestagent/strategies/backup/, InnoBackupExIncremental::cmd function in trove/guestagent/strategies/backup/, _get_actual_db_status function in trove/guestagent/datastore/experimental/cassandra/ and trove/guestagent/datastore/experimental/cassandra/, and multiple class CbBackup methods in trove/guestagent/strategies/backup/experimental/ in Openstack DBaaS (aka Trove) as packaged in Openstack before 2015.1.0 (aka Kilo) allows local users to write to configuration files via a symlink attack on a temporary file.

Vendor: Openstack
Product: Trove 
Version: 2014.2.4;

CVSS2 => (AV:L/AC:L/Au:N/C:N/I:P/A:N)

