CVE-2013-1815
PackStack 2012.2.3 in Red Hat OpenStack Essex and Folsom can create the answer file in insecure directories such as /tmp or the current working directory, which allows local users to modify deployed systems by changing this file.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.1
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
- EPSS probability
- 0.15%
- CWE
- CWE-379
- Published
- 2013-04-10
- Last modified
- 2026-04-30
Affected products
- n/a n/a
Weakness type
Related vulnerabilities
- CVE-2025-32438 — Local privilege escalation in make-initrd-ng
- CVE-2025-27148 — Gradle vulnerable to local privilege escalation through system temporary directory
- CVE-2023-49797 — Local Privilege Escalation in pyinstaller on Windows
- CVE-2021-29428 — Local privilege escalation through system temporary directory
- CVE-2024-9950 — Abuse of Unauthenticated Compliance Recheck in SecureConnector
- CVE-2021-21100 — Adobe Digital Editions Arbitrary file system write vulnerability
- CVE-2024-9500 — Autodesk ADP Desktop SDK Privilege Escalation Vulnerability
- CVE-2023-37243 — The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM w