Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3517

Опубликовано: 17 июл. 2014
Источник: redhat
CVSS2: 4.3

Описание

api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through Neutron, makes it easier for remote attackers to guess instance ID signatures via a brute-force attack that relies on timing differences in responses to instance metadata requests.

A side-channel timing attack flaw was found in Nova. An attacker could possibly use this flaw to guess valid instance ID signatures, giving them access to details of another instance, by analyzing the response times of requests for instance metadata. This issue only affected configurations that proxy metadata requests via Neutron.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 3openstack-novaWill not fix
OpenStack 4 for RHEL 6openstack-novaFixedRHSA-2014:108421.08.2014
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7openstack-novaFixedRHSA-2014:094024.07.2014

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-385
https://bugzilla.redhat.com/show_bug.cgi?id=1112499openstack-nova: timing attack issue allows access to other instances' configuration information

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through Neutron, makes it easier for remote attackers to guess instance ID signatures via a brute-force attack that relies on timing differences in responses to instance metadata requests.

nvd
больше 11 лет назад

api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through Neutron, makes it easier for remote attackers to guess instance ID signatures via a brute-force attack that relies on timing differences in responses to instance metadata requests.

debian
больше 11 лет назад

api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2 ...

github
больше 3 лет назад

OpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerability

4.3 Medium

CVSS2