CVE-2012-5476
published 2019-12-30CVE-2012-5476: Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the admin…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.40%
32.2th percentile
Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the admin password and token value.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | horizon | — | — |
| openstack-dashboard | openstack-dashboard | — | — |
| openstack | horizon | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_debian5.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2012-5476: horizon - Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the f...
vendor_debian·2012·CVSS 5.5
CVE-2012-5476 [MEDIUM] CVE-2012-5476: horizon - Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the f...
Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the admin password and token value.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-w8fv-pp3m-2hqx: Within the RHOS Essex Preview (2012
ghsa_unreviewed·2022-04-23
CVE-2012-5476 [MEDIUM] CWE-200 GHSA-w8fv-pp3m-2hqx: Within the RHOS Essex Preview (2012
Within the RHOS Essex Preview (2012.2) of the OpenStack dashboard package, the file /etc/quantum/quantum.conf is world readable which exposes the admin password and token value.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5476 OpenStack: Quantum /etc/quantum/quantum.conf secret password and token exposure [epel-6]
bugzilla·2012-11-13·CVSS 5.5
CVE-2012-5476 [MEDIUM] CVE-2012-5476 OpenStack: Quantum /etc/quantum/quantum.conf secret password and token exposure [epel-6]
CVE-2012-5476 OpenStack: Quantum /etc/quantum/quantum.conf secret password and token exposure [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available
Bugzilla
CVE-2012-5476 OpenStack: Quantum /etc/quantum/quantum.conf secret password and token exposure
bugzilla·2012-11-06·CVSS 5.5
CVE-2012-5476 [MEDIUM] CVE-2012-5476 OpenStack: Quantum /etc/quantum/quantum.conf secret password and token exposure
CVE-2012-5476 OpenStack: Quantum /etc/quantum/quantum.conf secret password and token exposure
Within the OpenStack Quantum package (specifically openstack-quantum) the
file Within the OpenStack dashboard package (specifically openstack-dashboard) the
file /etc/quantum/quantum.conf is world readable and contains:
===
[filter:authN]
...
auth_admin_user = admin
auth_admin_password = secrete
#auth_admin_token =
===
This file should be mode 0600.
Discussion:
Quantum config files are all
%config(noreplace) %attr(0640, root, quantum)
in 2012.2 (Folsom) so this only affects RHOS Essex Preview.
How urgent is to push this update to Essex Preview, when it is going public?
---
Created openstack-quantum tracking bugs for this issue
Affects: epel-6 [bug 876288]
---
python-keystoneclient-0.1.3.
https://access.redhat.com/security/cve/cve-2012-5476https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5476https://security-tracker.debian.org/tracker/CVE-2012-5476https://access.redhat.com/security/cve/cve-2012-5476https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2012-5476https://security-tracker.debian.org/tracker/CVE-2012-5476
2019-12-30
Published