4.3 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:M/Au:N/C:P/I:N/A:N
0.003 Low
EPSS
Percentile
70.0%
api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x
before 2014.1.2, and Juno before Juno-2, when proxying metadata requests
through Neutron, makes it easier for remote attackers to guess instance ID
signatures via a brute-force attack that relies on timing differences in
responses to instance metadata requests.
Author | Note |
---|---|
jdstrand | per upstream, Only setups configured to proxy metadata requests via Neutron are affected |