OpenStack Nova 'EC2_SECRET_KEY' Man In The Middle Security Bypass Vulnerability
BID:50359
Info
OpenStack Nova 'EC2_SECRET_KEY' Man In The Middle Security Bypass Vulnerability
| Bugtraq ID: | 50359 |
| Class: | Design Error |
| CVE: |
CVE-2011-4076 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 25 2011 12:00AM |
| Updated: | Apr 13 2015 09:15PM |
| Credit: | Stanislaw Pitucha |
| Vulnerable: |
Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 OpenStack Nova 0 |
| Not Vulnerable: | |
Discussion
OpenStack Nova 'EC2_SECRET_KEY' Man In The Middle Security Bypass Vulnerability
OpenStack Nova is prone to a security-bypass vulnerability.
Attackers can exploit this issue through man-in-the-middle attacks to gain knowledge of the 'EC2_SECRET_KEY'.
OpenStack Nova is prone to a security-bypass vulnerability.
Attackers can exploit this issue through man-in-the-middle attacks to gain knowledge of the 'EC2_SECRET_KEY'.
Exploit / POC
OpenStack Nova 'EC2_SECRET_KEY' Man In The Middle Security Bypass Vulnerability
An attacker may use readily available tools to exploit this issue.
An attacker may use readily available tools to exploit this issue.
Solution / Fix
OpenStack Nova 'EC2_SECRET_KEY' Man In The Middle Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
OpenStack Nova 'EC2_SECRET_KEY' Man In The Middle Security Bypass Vulnerability
References:
References:
- Change Idb31f076: Stop returning correct password on api calls (Open Stack)
- OpenStack Homepage (OpenStack)