CVE-2014-3517

Severity
4.3MEDIUM
EPSS
0.4%
top 39.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 7
Latest updateMay 14

Description

api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through Neutron, makes it easier for remote attackers to guess instance ID signatures via a brute-force attack that relies on timing differences in responses to instance metadata requests.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

NVDopenstack/nova2014.12014.1.2+2
PyPInova2014.0.02014.1.2+1
Debiannova< 2014.1.1-8+3

Patches

🔴Vulnerability Details

4
OSV
OpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerability2022-05-14
GHSA
OpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerability2022-05-14
CVEList
CVE-2014-3517: api/metadata/handler2014-08-07
OSV
CVE-2014-3517: api/metadata/handler2014-08-07

📋Vendor Advisories

3
Ubuntu
OpenStack Nova vulnerability2014-08-21
Red Hat
openstack-nova: timing attack issue allows access to other instances' configuration information2014-07-17
Debian
CVE-2014-3517: nova - api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x befo...2014

💬Community

4
Bugzilla
CVE-2014-3517 openstack-nova: timing attack issue allows access to other instances' configuration information [fedora-19]2014-07-18
Bugzilla
CVE-2014-3517 openstack-nova: timing attack issue allows access to other instances' configuration information [fedora-20]2014-07-18
Bugzilla
CVE-2014-3517 openstack-nova: timing attack issue allows access to other instances' configuration information [epel-6]2014-07-18
Bugzilla
CVE-2014-3517 openstack-nova: timing attack issue allows access to other instances' configuration information2014-06-24
CVE-2014-3517 (MEDIUM CVSS 4.3) | api/metadata/handler.py in OpenStac | cvebase.io