The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tripleo_heat_templates | Openstack | * | * |
Red Hat Enterprise Linux OpenStack Platform director 7.0 for RHEL 7 | RedHat | openstack-tripleo-heat-templates-0:0.8.6-94.el7ost | * |
Red Hat Enterprise Linux OpenStack Platform director 7.0 for RHEL 7 | RedHat | python-rdomanager-oscplugin-0:0.0.10-22.el7ost | * |
Tripleo-heat-templates | Ubuntu | esm-apps/xenial | * |
Tripleo-heat-templates | Ubuntu | trusty | * |
Tripleo-heat-templates | Ubuntu | upstream | * |
Tripleo-heat-templates | Ubuntu | xenial | * |