{
  "threat_severity" : "Low",
  "public_date" : "2012-05-26T00:00:00Z",
  "bugzilla" : {
    "description" : "python-keyring: weak encryption in keyring",
    "id" : "872260",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=872260"
  },
  "cvss" : {
    "cvss_base_score" : "2.1",
    "cvss_scoring_vector" : "AV:L/AC:L/Au:N/C:P/I:N/A:N",
    "status" : "draft"
  },
  "cwe" : "CWE-327",
  "details" : [ "Python Keyring 0.9.1 does not securely initialize the cipher when encrypting passwords for CryptedFileKeyring files, which makes it easier for local users to obtain passwords via a brute-force attack." ],
  "statement" : "Red Hat Product Security has rated this issue as having Low security impact in Red Hat OpenStack Platform 4.0. This issue is not currently planned to be addressed in future updates.",
  "package_state" : [ {
    "product_name" : "Red Hat OpenStack Platform 3",
    "fix_state" : "Will not fix",
    "package_name" : "python-keyring",
    "cpe" : "cpe:/a:redhat:openstack:3"
  }, {
    "product_name" : "Red Hat OpenStack Platform 4",
    "fix_state" : "Will not fix",
    "package_name" : "python-keyring",
    "cpe" : "cpe:/a:redhat:openstack:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2012-4571\nhttps://nvd.nist.gov/vuln/detail/CVE-2012-4571" ],
  "name" : "CVE-2012-4571",
  "csaw" : false
}