oss-sec mailing list archives
CVE request: nova
From: Jamie Strandboge <jamie () canonical com>
Date: Tue, 25 Oct 2011 12:11:51 -0500
A flaw was discovered in OpenStack nova[1] which allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC2_SECRET_KEY (equivalent to a password). While the EC2_ACCESS_KEY is typically not public, if the user exposes it via http or tools that allow MITM over https, then an attacker could obtain the EC2_SECRET_KEY easily. An attacker could also presumably brute force values for EC2_ACCESS_KEY. Fix: https://review.openstack.org/#change,794 [1]https://launchpad.net/bugs/868360 -- Jamie Strandboge | http://www.canonical.com
Attachment:
signature.asc
Description: This is a digitally signed message part
Current thread:
- CVE request: nova Jamie Strandboge (Oct 25)
- Re: CVE request: nova Kurt Seifried (Oct 25)