CVE-2012-5474
published 2019-12-30CVE-2012-5474: The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1)…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.34%
25.9th percentile
The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | horizon | < horizon 2012.1.1-7 (bookworm) | horizon 2012.1.1-7 (bookworm) |
| fedoraproject | fedora | — | — |
| openstack | horizon | >= 0 < 2012.1.1-7 | 2012.1.1-7 |
| openstack | horizon | >= 0 < 2012.1.1-7 | 2012.1.1-7 |
| openstack | horizon | >= 0 < 2012.1.1-7 | 2012.1.1-7 |
| openstack | horizon | >= 0 < 2012.1.1-7 | 2012.1.1-7 |
| openstack | horizon | >= 2012.1 < 2012.1.1 | 2012.1.1 |
| python-django-horizon | python-django-horizon | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4q46-pmqc-c3vc: The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2
ghsa_unreviewed·2022-04-23
CVE-2012-5474 [MEDIUM] CWE-311 GHSA-4q46-pmqc-c3vc: The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2
The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.
OSV
CVE-2012-5474: The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2
osv·2019-12-30·CVSS 5.5
CVE-2012-5474 [MEDIUM] CVE-2012-5474: The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2
The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.
Debian
CVE-2012-5474: horizon - The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platfo...
vendor_debian·2012·CVSS 5.5
CVE-2012-5474 [MEDIUM] CVE-2012-5474: horizon - The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platfo...
The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.
Scope: local
bookworm: resolved (fixed in 2012.1.1-7)
bullseye: resolved (fixed in 2012.1.1-7)
forky: resolved (fixed in 2012.1.1-7)
sid: resolved (fixed in 2012.1.1-7)
trixie: resolved (fixed in 2012.1.1-7)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5474 OpenStack: Dashboard /etc/openstack-dashboard/local_settings secret key exposure [epel-6]
bugzilla·2012-11-13·CVSS 5.5
CVE-2012-5474 [MEDIUM] CVE-2012-5474 OpenStack: Dashboard /etc/openstack-dashboard/local_settings secret key exposure [epel-6]
CVE-2012-5474 OpenStack: Dashboard /etc/openstack-dashboard/local_settings secret key exposure [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availabl
Bugzilla
CVE-2012-5474 OpenStack: Dashboard /etc/openstack-dashboard/local_settings secret key exposure
bugzilla·2012-11-05·CVSS 5.5
CVE-2012-5474 [MEDIUM] CVE-2012-5474 OpenStack: Dashboard /etc/openstack-dashboard/local_settings secret key exposure
CVE-2012-5474 OpenStack: Dashboard /etc/openstack-dashboard/local_settings secret key exposure
Within the OpenStack dashboard package (specifically openstack-dashboard) the
file /etc/openstack-dashboard/local_settings is world readable and contains:
===
# Note: You should change this value
SECRET_KEY = 'elj1IWiLoWHgcyYxFVLj7cM5rGOOxWl0'
===
Also as a note the same value is contained within:
/usr/share/openstack-dashboard/openstack_dashboard/local/local_settings.py
This file needs to be read by the web server (apache HTTPD), so a reasonable
file configuration would be to set the file as owned by the root user and the
apache group with file mode 0640.
As I understand it this value is no longer used in the Folsom release of
OpenStack.
Discussion:
Created python-django-horizon tracking
http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092841.htmlhttps://access.redhat.com/security/cve/cve-2012-5474https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5474https://security-tracker.debian.org/tracker/CVE-2012-5474http://lists.fedoraproject.org/pipermail/package-announce/2012-November/092841.htmlhttps://access.redhat.com/security/cve/cve-2012-5474https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5474https://security-tracker.debian.org/tracker/CVE-2012-5474
2019-12-30
Published