CVE-2011-4076
OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC2_SECRET_KEY (equivalent to a password). Exposing the EC2_ACCESS_KEY via http or tools that allow man-in-the-middle over https could allow an attacker to easily obtain the EC2_SECRET_KEY. An attacker could also presumably brute force values for EC2_ACCESS_KEY.
- Affected products
- Openstack Nova
- Openstack Nova
- < 2012.1
- Fix
- Available
- CVSS 3.1
- 5.9 MEDIUM
- EPSS
- 1.5% (72th percentile)
- Weakness
- CWE-200
- NVD status
- Modified
- Published
- 2019-11-26
CVE-2011-4076 at NVD
No indexed exploits for CVE-2011-4076 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2011-4076 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.