CVE Vulnerabilities

CVE-2012-5483

Published: Dec 26, 2012 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM

tools/sample_data.sh in OpenStack Keystone 2012.1.3, when access to Amazon Elastic Compute Cloud (Amazon EC2) is configured, uses world-readable permissions for /etc/keystone/ec2rc, which allows local users to obtain access to EC2 services by reading administrative access and secret values from this file.

Affected Software

Name Vendor Start Version End Version
Keystone Openstack 2012.1.3 (including) 2012.1.3 (including)
OpenStack Essex for RHEL 6 RedHat openstack-keystone-0:2012.1.3-3.el6 *

References