CVE-2015-5303

Severity CVSS v4.0:
Pending analysis
Type:
CWE-254 Security Features
Publication date:
11/04/2016
Last modified:
12/04/2025

Description

The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:openstack:tripleo_heat_templates:*:*:*:*:*:*:*:*