Safety vulnerability ID: 37736
The information on this page was manually curated by our Cybersecurity Intelligence Team.
OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC2_SECRET_KEY (equivalent to a password). Exposing the EC2_ACCESS_KEY via http or tools that allow man-in-the-middle over https could allow an attacker to easily obtain the EC2_SECRET_KEY. An attacker could also presumably brute force values for EC2_ACCESS_KEY. See CVE-2011-4076.
Latest version: 30.0.0
Cloud computing fabric controller
OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC2_SECRET_KEY (equivalent to a password). Exposing the EC2_ACCESS_KEY via http or tools that allow man-in-the-middle over https could allow an attacker to easily obtain the EC2_SECRET_KEY. An attacker could also presumably brute force values for EC2_ACCESS_KEY.
MISC:https://access.redhat.com/security/cve/cve-2011-4076: https://access.redhat.com/security/cve/cve-2011-4076
MISC:https://bugs.launchpad.net/nova/+bug/868360: https://bugs.launchpad.net/nova/+bug/868360
MISC:https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-4076: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-4076
MISC:https://security-tracker.debian.org/tracker/CVE-2011-4076: https://security-tracker.debian.org/tracker/CVE-2011-4076
MISC:https://www.openwall.com/lists/oss-security/2011/10/25/4: https://www.openwall.com/lists/oss-security/2011/10/25/4
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application