Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:11871
HistoryJan 15, 2019 - 9:09 a.m.

Spoofing Metadata Requests

2019-01-1509:09:13
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
2

0.002 Low

EPSS

Percentile

55.6%

tripleo-heat-templates is vulnerable to spoofing of metadata requests. It is due to having the bad default setting of a blank value for the NeutronMetadataProxySharedSecret parameter when it is deployed from the command line interface. Not setting the value to this parameter means Neutron does not prevent spoofing, allowing attackers to spoof OpenStack Networking metadata requests.

References

0.002 Low

EPSS

Percentile

55.6%