REDHAT-BUG-873447: Low severity keystone vulnerability
Within the OpenStack keystone package the file /etc/keystone/ec2rc is world readable and contains:
=== ADMINACCESS=109a7daa83054fc58ec8ade83b114117 ADMINSECRET=3bbbcba9514e4e8e8d0eb9e528754091 DEMOACCESS=81c2326383e34b888e0589057bc7fae2 DEMOSECRET=ceb87a47838a442ea2923ad1bd6f0a16 ===
Also please note that the /etc/keystone/ directory should probably not be world readable at all.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-873447?
The severity of REDHAT-BUG-873447 is critical due to the exposure of sensitive credentials in a world-readable file.
How do I fix REDHAT-BUG-873447?
To fix REDHAT-BUG-873447, change the permissions of the /etc/keystone/ec2rc file to restrict access.
What components are affected by REDHAT-BUG-873447?
The components affected by REDHAT-BUG-873447 are the OpenStack keystone package.
What credentials are exposed in REDHAT-BUG-873447?
REDHAT-BUG-873447 exposes the ADMIN_ACCESS, ADMIN_SECRET, DEMO_ACCESS, and DEMO_SECRET credentials.
What security risks does REDHAT-BUG-873447 pose?
REDHAT-BUG-873447 poses a security risk of unauthorized access to the OpenStack environment due to exposed sensitive information.