CVE Vulnerabilities

CVE-2015-5303

Published: Apr 11, 2016 | Modified: Apr 18, 2016
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM

The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.

Affected Software

Name Vendor Start Version End Version
Tripleo_heat_templates Openstack * *
Red Hat Enterprise Linux OpenStack Platform director 7.0 for RHEL 7 RedHat openstack-tripleo-heat-templates-0:0.8.6-94.el7ost *
Red Hat Enterprise Linux OpenStack Platform director 7.0 for RHEL 7 RedHat python-rdomanager-oscplugin-0:0.0.10-22.el7ost *
Tripleo-heat-templates Ubuntu esm-apps/xenial *
Tripleo-heat-templates Ubuntu trusty *
Tripleo-heat-templates Ubuntu upstream *
Tripleo-heat-templates Ubuntu xenial *

References