CVE-2014-3517
published 2014-08-07CVE-2014-3517: api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through…
medium4.3CVSS 3.1
AVNACMAuNCPINAN
api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through Neutron, makes it easier for remote attackers to guess instance ID signatures via a brute-force attack that relies on timing differences in responses to instance metadata requests.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2014.1.1-8 (bookworm) | nova 2014.1.1-8 (bookworm) |
| openstack | nova | — | — |
| openstack | nova | >= 0 < 2014.1.1-8 | 2014.1.1-8 |
| openstack | nova | >= 0 < 2014.1.1-8 | 2014.1.1-8 |
| openstack | nova | >= 0 < 2014.1.1-8 | 2014.1.1-8 |
| openstack | nova | >= 0 < 2014.1.1-8 | 2014.1.1-8 |
| openstack | nova | >= 0 < 2013.2.4 | 2013.2.4 |
| openstack | nova | 2013.2 – 2013.2.4 | — |
| openstack | nova | >= 2014.0.0 < 2014.1.2 | 2014.1.2 |
| openstack | nova | >= 2014.1 < 2014.1.2 | 2014.1.2 |
CVSS provenance
nvd4.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM