Openstack · Openstack · CVE-2012-5476
**Name of the Vulnerable Software and Affected Versions**
OpenStack dashboard package version 2012.2
**Description**
The issue concerns a file, /etc/quantum/quantum.conf, being world readable. This exposes sensitive information, including the admin password and token value.
**Recommendations**
For version 2012.2, restrict access to the /etc/quantum/quantum.conf file to prevent unauthorized reading of the admin password and token value. As a temporary workaround, consider changing the file permissions to limit access until a more permanent solution is available.