---
id: CVE-2022-3101
aliases:
  - GHSA-7x96-2w32-w3gw
  - PYSEC-2026-1051
title: >-
  tripleo-ansible may disclose important configuration details from an OpenStack
  deployment
summary: >-
  tripleo-ansible may disclose important configuration details from an OpenStack
  deployment
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
vendor: tripleo-ansible
product: tripleo-ansible
ecosystem: pip
affected:
  - tripleo-ansible <= 6.0.0
published: '2023-03-23'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-7x96-2w32-w3gw'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2022-3101'
  - url: 'https://access.redhat.com/security/cve/CVE-2022-3101'
  - url: 'https://github.com/openstack/tripleo-ansible'
tags:
  - osv
  - pip
epss: 0.00202
epssPercentile: 0.10495
ingestedAt: '2026-07-08T18:25:47.253Z'
---

## Overview

A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to information disclosure of important configuration details from the OpenStack deployment.

## Affected packages

- `tripleo-ansible <= 6.0.0`

## Remediation

Refer to the advisory for the patched release.
