cbcvebase.
CVE-2014-3517
published 2014-08-07

CVE-2014-3517: api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through…

medium4.3CVSS 3.1
AVNACMAuNCPINAN
api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through Neutron, makes it easier for remote attackers to guess instance ID signatures via a brute-force attack that relies on timing differences in responses to instance metadata requests.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiannova< nova 2014.1.1-8 (bookworm)nova 2014.1.1-8 (bookworm)
openstacknova
openstacknova>= 0 < 2014.1.1-82014.1.1-8
openstacknova>= 0 < 2014.1.1-82014.1.1-8
openstacknova>= 0 < 2014.1.1-82014.1.1-8
openstacknova>= 0 < 2014.1.1-82014.1.1-8
openstacknova>= 0 < 2013.2.42013.2.4
openstacknova2013.2 – 2013.2.4
openstacknova>= 2014.0.0 < 2014.1.22014.1.2
openstacknova>= 2014.1 < 2014.1.22014.1.2

CVSS provenance

nvd4.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv4.3MEDIUM