Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5303

Опубликовано: 09 дек. 2015
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.

It was discovered that Director's NeutronMetadataProxySharedSecret parameter remained specified at the default value of 'unset'. This value is used by OpenStack Networking to sign instance headers; if unchanged, an attacker knowing the shared secret could use this flaw to spoof OpenStack Networking metadata requests.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 8 (Liberty) Directorpython-tripleoclientNot affected
Red Hat Enterprise Linux OpenStack Platform director 7.0 for RHEL 7openstack-tripleo-heat-templatesFixedRHSA-2015:265021.12.2015
Red Hat Enterprise Linux OpenStack Platform director 7.0 for RHEL 7python-rdomanager-oscpluginFixedRHSA-2015:265021.12.2015

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1272297python-rdomanager-oscplugin: NeutronMetadataProxySharedSecret parameter uses default value

EPSS

Процентиль: 55%
0.00326
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 10 лет назад

The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.

CVSS3: 7.5
nvd
почти 10 лет назад

The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.

CVSS3: 7.5
debian
почти 10 лет назад

The TripleO Heat templates (tripleo-heat-templates), when deployed via ...

CVSS3: 7.5
github
больше 3 лет назад

OpenStack TripleO Heat templates spoof metadata requests

EPSS

Процентиль: 55%
0.00326
Низкий

4.3 Medium

CVSS2