Nixpkgs security tracker

Login with GitHub
⚠️ You are using a production deployment that is still only suitable for demo purposes. Any work done in this might be wiped later without notice.

Suggestion detail

Untriaged
created 2 months ago Activity log
  • Created suggestion
OpenStack Nova before 2012.1 allows someone with access to an …

OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC2_SECRET_KEY (equivalent to a password). Exposing the EC2_ACCESS_KEY via http or tools that allow man-in-the-middle over https could allow an attacker to easily obtain the EC2_SECRET_KEY. An attacker could also presumably brute force values for EC2_ACCESS_KEY.

Affected products

nova
  • ==2014.1.3-11

Matching in nixpkgs

pkgs.nova

Find outdated or deprecated Helm charts running in your cluster

pkgs.libnova

Celestial Mechanics, Astrometry and Astrodynamics Library

  • nixos-unstable 0.16
    • nixpkgs-unstable 0.16
    • nixos-unstable-small 0.16
  • nixos-25.11 0.16
    • nixos-25.11-small 0.16
    • nixpkgs-25.11-darwin 0.16

pkgs.supernovas

High-performance astrometry library for C/C++

pkgs.webos.novacom

Utility for communicating with WebOS devices

  • nixos-unstable 18
    • nixpkgs-unstable 18
    • nixos-unstable-small 18
  • nixos-25.11 18
    • nixos-25.11-small 18
    • nixpkgs-25.11-darwin 18

pkgs.webos.novacomd

Daemon for communicating with WebOS devices

  • nixos-unstable 127
    • nixpkgs-unstable 127
    • nixos-unstable-small 127
  • nixos-25.11 127
    • nixos-25.11-small 127
    • nixpkgs-25.11-darwin 127

Package maintainers