CVE Vulnerabilities

CVE-2015-5303

Published: Apr 11, 2016 | Modified: Apr 12, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.

Affected Software

NameVendorStart VersionEnd Version
Tripleo_heat_templatesOpenstack**
Red Hat Enterprise Linux OpenStack Platform director 7.0 for RHEL 7RedHatopenstack-tripleo-heat-templates-0:0.8.6-94.el7ost*
Red Hat Enterprise Linux OpenStack Platform director 7.0 for RHEL 7RedHatpython-rdomanager-oscplugin-0:0.0.10-22.el7ost*
Tripleo-heat-templatesUbuntuesm-apps/xenial*
Tripleo-heat-templatesUbuntutrusty*
Tripleo-heat-templatesUbuntuupstream*
Tripleo-heat-templatesUbuntuxenial*

References