Total vulnerabilities in the database
The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.
Software | From | Fixed in |
---|---|---|
redhat / openstack | 2.0 | 2.0.x |
openstack / horizon | 2012.1 | 2012.1.1 |
debian / debian_linux | 8.0 | 8.0.x |
debian / debian_linux | 9.0 | 9.0.x |
debian / debian_linux | 10.0 | 10.0.x |
fedoraproject / fedora | 18 | 18.x |