CVE-2014-3517
published 2014-08-07CVE-2014-3517: api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through…
PriorityP421medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.94%
77.9th percentile
api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through Neutron, makes it easier for remote attackers to guess instance ID signatures via a brute-force attack that relies on timing differences in responses to instance metadata requests.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nova | < nova 2014.1.1-8 (bookworm) | nova 2014.1.1-8 (bookworm) |
| openstack | nova | — | — |
| openstack | nova | >= 0 < 2014.1.1-8 | 2014.1.1-8 |
| openstack | nova | >= 0 < 2014.1.1-8 | 2014.1.1-8 |
| openstack | nova | >= 0 < 2014.1.1-8 | 2014.1.1-8 |
| openstack | nova | >= 0 < 2014.1.1-8 | 2014.1.1-8 |
| openstack | nova | >= 0 < 2013.2.4 | 2013.2.4 |
| openstack | nova | 2013.2 – 2013.2.4 | — |
| openstack | nova | >= 2014.0.0 < 2014.1.2 | 2014.1.2 |
| openstack | nova | >= 2014.1 < 2014.1.2 | 2014.1.2 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
OpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerability
osv·2022-05-14
CVE-2014-3517 [MEDIUM] OpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerability
OpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerability
api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through Neutron, makes it easier for remote attackers to guess instance ID signatures via a brute-force attack that relies on timing differences in responses to instance metadata requests.
GHSA
OpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerability
ghsa·2022-05-14
CVE-2014-3517 [MEDIUM] CWE-200 OpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerability
OpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerability
api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through Neutron, makes it easier for remote attackers to guess instance ID signatures via a brute-force attack that relies on timing differences in responses to instance metadata requests.
OSV
CVE-2014-3517: api/metadata/handler
osv·2014-08-07·CVSS 4.3
CVE-2014-3517 [MEDIUM] CVE-2014-3517: api/metadata/handler
api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through Neutron, makes it easier for remote attackers to guess instance ID signatures via a brute-force attack that relies on timing differences in responses to instance metadata requests.
Ubuntu
OpenStack Nova vulnerability
vendor_ubuntu·2014-08-21
CVE-2014-3517 OpenStack Nova vulnerability
Title: OpenStack Nova vulnerability
Summary: OpenStack Nova could be made to expose sensitive information over the
network.
Alex Gaynor discovered that OpenStack Nova would sometimes respond with
variable times when comparing authentication tokens. If nova were
configured to proxy metadata requests via Neutron, a remote authenticated
attacker could exploit this to conduct timing attacks and ascertain
configuration details of another instance.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openstack-nova: timing attack issue allows access to other instances' configuration information
vendor_redhat·2014-07-17·CVSS 4.3
CVE-2014-3517 [MEDIUM] CWE-385 openstack-nova: timing attack issue allows access to other instances' configuration information
openstack-nova: timing attack issue allows access to other instances' configuration information
api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through Neutron, makes it easier for remote attackers to guess instance ID signatures via a brute-force attack that relies on timing differences in responses to instance metadata requests.
A side-channel timing attack flaw was found in Nova. An attacker could possibly use this flaw to guess valid instance ID signatures, giving them access to details of another instance, by analyzing the response times of requests for instance metadata. This issue only affected configurations that proxy metadata requests via Neutron.
Package: openstack-nova (Red H
Debian
CVE-2014-3517: nova - api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x befo...
vendor_debian·2014·CVSS 4.3
CVE-2014-3517 [MEDIUM] CVE-2014-3517: nova - api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x befo...
api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through Neutron, makes it easier for remote attackers to guess instance ID signatures via a brute-force attack that relies on timing differences in responses to instance metadata requests.
Scope: local
bookworm: resolved (fixed in 2014.1.1-8)
bullseye: resolved (fixed in 2014.1.1-8)
forky: resolved (fixed in 2014.1.1-8)
sid: resolved (fixed in 2014.1.1-8)
trixie: resolved (fixed in 2014.1.1-8)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3517 openstack-nova: timing attack issue allows access to other instances' configuration information [fedora-19]
bugzilla·2014-07-18·CVSS 4.3
CVE-2014-3517 [MEDIUM] CVE-2014-3517 openstack-nova: timing attack issue allows access to other instances' configuration information [fedora-19]
CVE-2014-3517 openstack-nova: timing attack issue allows access to other instances' configuration information [fedora-19]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
fedora-19 tr
Bugzilla
CVE-2014-3517 openstack-nova: timing attack issue allows access to other instances' configuration information [fedora-20]
bugzilla·2014-07-18·CVSS 4.3
CVE-2014-3517 [MEDIUM] CVE-2014-3517 openstack-nova: timing attack issue allows access to other instances' configuration information [fedora-20]
CVE-2014-3517 openstack-nova: timing attack issue allows access to other instances' configuration information [fedora-20]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
fedora-20 tr
Bugzilla
CVE-2014-3517 openstack-nova: timing attack issue allows access to other instances' configuration information [epel-6]
bugzilla·2014-07-18·CVSS 4.3
CVE-2014-3517 [MEDIUM] CVE-2014-3517 openstack-nova: timing attack issue allows access to other instances' configuration information [epel-6]
CVE-2014-3517 openstack-nova: timing attack issue allows access to other instances' configuration information [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-6 tra
Bugzilla
CVE-2014-3517 openstack-nova: timing attack issue allows access to other instances' configuration information
bugzilla·2014-06-24·CVSS 4.3
CVE-2014-3517 [MEDIUM] CVE-2014-3517 openstack-nova: timing attack issue allows access to other instances' configuration information
CVE-2014-3517 openstack-nova: timing attack issue allows access to other instances' configuration information
The OpenStack project reports:
""
Title: Use of non-constant time comparison operation
Reporter: Alex Gaynor (Rackspace)
Products: Nova
Versions: Up to 2013.2.3, and 2014.1 to 2014.1.1
Alex Gaynor from Rackspace reported a timing attack vulnerability in
Nova. By analyzing response times to requests for instance metadata, an
attacker may be able to guess a valid instance ID signature. This could
allow access to important configuration details of another instance.
Only setups configured to proxy metadata requests via Neutron are affected.
""
Acknowledgements:
Red Hat would like to thank the OpenStack project for reporting this issue. Upstream acknowledges Alex Gaynor from Racksp
2014-08-07
Published