Safety vulnerability ID: 37741
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Horizon 2012.1.1 includes a fix for CVE-2012-5474: The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5474
Latest version: 25.1.0
OpenStack Dashboard
The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.
MISC:http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092841.html: http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092841.html
MISC:https://access.redhat.com/security/cve/cve-2012-5474: https://access.redhat.com/security/cve/cve-2012-5474
MISC:https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5474: https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5474
MISC:https://security-tracker.debian.org/tracker/CVE-2012-5474: https://security-tracker.debian.org/tracker/CVE-2012-5474
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application