CVE-2011-4076 describes a vulnerability in OpenStack Nova before version 2012.1, where an attacker with an EC2_ACCESS_KEY could obtain the corresponding EC2_SECRET_KEY. This medium-severity vulnerability (CVSS 5.9) has a network attack vector and high confidentiality impact, as it could lead to unauthorized access to cloud resources. While it has no known active exploitation, public exploit code, or significant community discussion, its potential for sensitive information disclosure warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2010.1, < 2012.1CPE matchmatch criteria | cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.