CVE-2012-5483
published 2012-12-26CVE-2012-5483: tools/sample_data.sh in OpenStack Keystone 2012.1.3, when access to Amazon Elastic Compute Cloud (Amazon EC2) is configured, uses world-readable permissions…
PriorityP47low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.34%
26.9th percentile
tools/sample_data.sh in OpenStack Keystone 2012.1.3, when access to Amazon Elastic Compute Cloud (Amazon EC2) is configured, uses world-readable permissions for /etc/keystone/ec2rc, which allows local users to obtain access to EC2 services by reading administrative access and secret values from this file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | keystone | — | — |
| openstack | keystone | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
OpenStack: Keystone /etc/keystone/ec2rc secret key exposure
vendor_redhat·2012-11-13·CVSS 2.1
CVE-2012-5483 [LOW] OpenStack: Keystone /etc/keystone/ec2rc secret key exposure
OpenStack: Keystone /etc/keystone/ec2rc secret key exposure
tools/sample_data.sh in OpenStack Keystone 2012.1.3, when access to Amazon Elastic Compute Cloud (Amazon EC2) is configured, uses world-readable permissions for /etc/keystone/ec2rc, which allows local users to obtain access to EC2 services by reading administrative access and secret values from this file.
Debian
CVE-2012-5483: keystone - tools/sample_data.sh in OpenStack Keystone 2012.1.3, when access to Amazon Elast...
vendor_debian·2012·CVSS 2.1
CVE-2012-5483 [LOW] CVE-2012-5483: keystone - tools/sample_data.sh in OpenStack Keystone 2012.1.3, when access to Amazon Elast...
tools/sample_data.sh in OpenStack Keystone 2012.1.3, when access to Amazon Elastic Compute Cloud (Amazon EC2) is configured, uses world-readable permissions for /etc/keystone/ec2rc, which allows local users to obtain access to EC2 services by reading administrative access and secret values from this file.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-8cx8-xmvm-66wj: tools/sample_data
ghsa_unreviewed·2022-05-17
CVE-2012-5483 [LOW] GHSA-8cx8-xmvm-66wj: tools/sample_data
tools/sample_data.sh in OpenStack Keystone 2012.1.3, when access to Amazon Elastic Compute Cloud (Amazon EC2) is configured, uses world-readable permissions for /etc/keystone/ec2rc, which allows local users to obtain access to EC2 services by reading administrative access and secret values from this file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-5483 OpenStack: Keystone /etc/keystone/ec2rc secret key exposure [epel-6]
bugzilla·2012-11-13·CVSS 2.1
CVE-2012-5483 [LOW] CVE-2012-5483 OpenStack: Keystone /etc/keystone/ec2rc secret key exposure [epel-6]
CVE-2012-5483 OpenStack: Keystone /etc/keystone/ec2rc secret key exposure [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-6 tracking b
Bugzilla
CVE-2012-5483 OpenStack: Keystone /etc/keystone/ec2rc secret key exposure
bugzilla·2012-11-05·CVSS 2.1
CVE-2012-5483 [LOW] CVE-2012-5483 OpenStack: Keystone /etc/keystone/ec2rc secret key exposure
CVE-2012-5483 OpenStack: Keystone /etc/keystone/ec2rc secret key exposure
Within the OpenStack keystone package the file /etc/keystone/ec2rc is world
readable and contains:
===
ADMIN_ACCESS=109a7daa83054fc58ec8ade83b114117
ADMIN_SECRET=3bbbcba9514e4e8e8d0eb9e528754091
DEMO_ACCESS=81c2326383e34b888e0589057bc7fae2
DEMO_SECRET=ceb87a47838a442ea2923ad1bd6f0a16
===
Also please note that the /etc/keystone/ directory should probably not be world
readable at all.
Discussion:
/etc/keystone/ec2rc is not included in openstack-keystone RPM, it's produced by sample_data.sh script
https://github.com/openstack/keystone/blob/master/tools/sample_data.sh#L259
We'll patch that part out, neither sample script nor ec2rc file is documented in our guide: https://access.redhat.com/knowledge/docs/en-US/Red_H
http://lists.fedoraproject.org/pipermail/package-announce/2012-December/094286.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1556.htmlhttp://www.securityfocus.com/bid/56888https://bugzilla.redhat.com/show_bug.cgi?id=873447https://exchange.xforce.ibmcloud.com/vulnerabilities/80612http://lists.fedoraproject.org/pipermail/package-announce/2012-December/094286.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1556.htmlhttp://www.securityfocus.com/bid/56888https://bugzilla.redhat.com/show_bug.cgi?id=873447https://exchange.xforce.ibmcloud.com/vulnerabilities/80612
2012-12-26
Published