Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog
Консоль
Π›ΠΎΠ³ΠΎΡ‚ΠΈΠΏ exploitDog

exploitDog

redhat Π»ΠΎΠ³ΠΎΡ‚ΠΈΠΏ

CVE-2015-5303

ΠžΠΏΡƒΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½ΠΎ: 09 Π΄Π΅ΠΊ. 2015
Π˜ΡΡ‚ΠΎΡ‡Π½ΠΈΠΊ: redhat
CVSS2: 4.3
EPSS Низкий

ОписаниС

The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.

It was discovered that Director's NeutronMetadataProxySharedSecret parameter remained specified at the default value of 'unset'. This value is used by OpenStack Networking to sign instance headers; if unchanged, an attacker knowing the shared secret could use this flaw to spoof OpenStack Networking metadata requests.

Π—Π°Ρ‚Ρ€ΠΎΠ½ΡƒΡ‚Ρ‹Π΅ ΠΏΠ°ΠΊΠ΅Ρ‚Ρ‹

ΠŸΠ»Π°Ρ‚Ρ„ΠΎΡ€ΠΌΠ°ΠŸΠ°ΠΊΠ΅Ρ‚Π‘ΠΎΡΡ‚ΠΎΡΠ½ΠΈΠ΅Π Π΅ΠΊΠΎΠΌΠ΅Π½Π΄Π°Ρ†ΠΈΡΠ Π΅Π»ΠΈΠ·
Red Hat OpenStack Platform 8 (Liberty) Directorpython-tripleoclientNot affected
Red Hat Enterprise Linux OpenStack Platform director 7.0 for RHEL 7openstack-tripleo-heat-templatesFixedRHSA-2015:265021.12.2015
Red Hat Enterprise Linux OpenStack Platform director 7.0 for RHEL 7python-rdomanager-oscpluginFixedRHSA-2015:265021.12.2015

ΠŸΠΎΠΊΠ°Π·Ρ‹Π²Π°Ρ‚ΡŒ ΠΏΠΎ

Бсылки Π½Π° источники

Π”ΠΎΠΏΠΎΠ»Π½ΠΈΡ‚Π΅Π»ΡŒΠ½Π°Ρ информация

Бтатус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1272297python-rdomanager-oscplugin: NeutronMetadataProxySharedSecret parameter uses default value

EPSS

ΠŸΡ€ΠΎΡ†Π΅Π½Ρ‚ΠΈΠ»ΡŒ: 75%
0.01665
Низкий

4.3 Medium

CVSS2

БвязанныС уязвимости

CVSS3: 7.5
ubuntu
большС 10 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.

CVSS3: 7.5
nvd
большС 10 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.

CVSS3: 7.5
debian
большС 10 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

The TripleO Heat templates (tripleo-heat-templates), when deployed via ...

CVSS3: 7.5
github
ΠΎΠΊΠΎΠ»ΠΎ 4 Π»Π΅Ρ‚ Π½Π°Π·Π°Π΄

OpenStack TripleO Heat templates spoof metadata requests

EPSS

ΠŸΡ€ΠΎΡ†Π΅Π½Ρ‚ΠΈΠ»ΡŒ: 75%
0.01665
Низкий

4.3 Medium

CVSS2

Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡ‚ΡŒ CVE-2015-5303