Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m94p-8942-pm49

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

OpenStack TripleO Heat templates spoof metadata requests

The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.

Пакеты

Наименование

tripleo-heat-templates

pip
Затронутые версииВерсия исправления

< 0.8.10

0.8.10

EPSS

Процентиль: 74%
0.01651
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 10 лет назад

The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.

redhat
больше 10 лет назад

The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.

CVSS3: 7.5
nvd
больше 10 лет назад

The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.

CVSS3: 7.5
debian
больше 10 лет назад

The TripleO Heat templates (tripleo-heat-templates), when deployed via ...

EPSS

Процентиль: 74%
0.01651
Низкий

8.7 High

CVSS4

7.5 High

CVSS3