CVE-2015-5303

Impact:
Moderate
Public Date:
2015-12-09
Bugzilla:
1272297: CVE-2015-5303 python-rdomanager-oscplugin: NeutronMetadataProxySharedSecret parameter uses default value
It was discovered that Director's NeutronMetadataProxySharedSecret parameter remained specified at the default value of 'unset'. This value is used by OpenStack Networking to sign instance headers; if unchanged, an attacker knowing the shared secret could use this flaw to spoof OpenStack Networking metadata requests.

Find out more about CVE-2015-5303 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 4.3
Base Metrics AV:N/AC:M/Au:N/C:P/I:N/A:N
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
OpenStack 7.0 Director for RHEL 7 (python-rdomanager-oscplugin) RHSA-2015:2650 2015-12-21

Affected Packages State

Platform Package State
OpenStack 8.0 Director for RHEL 7 python-tripleoclient Not affected

Acknowledgements

This issue was discovered by Steven Hardy of Red Hat.

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.