Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m94p-8942-pm49

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

OpenStack TripleO Heat templates spoof metadata requests

The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.

Пакеты

Наименование

tripleo-heat-templates

pip
Затронутые версииВерсия исправления

< 0.8.10

0.8.10

EPSS

Процентиль: 55%
0.00326
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 10 лет назад

The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.

redhat
около 10 лет назад

The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.

CVSS3: 7.5
nvd
почти 10 лет назад

The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.

CVSS3: 7.5
debian
почти 10 лет назад

The TripleO Heat templates (tripleo-heat-templates), when deployed via ...

EPSS

Процентиль: 55%
0.00326
Низкий

8.7 High

CVSS4

7.5 High

CVSS3