OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC2_SECRET_KEY (equivalent to a password). Exposing the EC2_ACCESS_KEY via http or tools that allow man-in-the-middle over https could allow an attacker to easily obtain the EC2_SECRET_KEY. An attacker could also presumably brute force values for EC2_ACCESS_KEY.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-1837 OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC2_SECRET_KEY (equivalent to a password). Exposing the EC2_ACCESS_KEY via http or tools that allow man-in-the-middle over https could allow an attacker to easily obtain the EC2_SECRET_KEY. An attacker could also presumably brute force values for EC2_ACCESS_KEY.
Github GHSA Github GHSA GHSA-vcmv-6rxx-fh7r OpenStack Nova Exposure of Sensitive Information to an Unauthorized Actor
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-06T23:53:32.881Z

Reserved: 2011-10-18T00:00:00

Link: CVE-2011-4076

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-11-26T04:15:11.137

Modified: 2024-11-21T01:31:47.983

Link: CVE-2011-4076

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses