CVE-2014-3517: Infoleak
api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through Neutron, makes it easier for remote attackers to guess instance ID signatures via a brute-force attack that relies on timing differences in responses to instance metadata requests.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3517?
CVE-2014-3517 has a medium severity rating due to potential exposure to brute-force attacks.
How do I fix CVE-2014-3517?
To fix CVE-2014-3517, upgrade OpenStack Nova to version 2013.2.4, 2014.1.2, or later.
Which versions of OpenStack Nova are affected by CVE-2014-3517?
CVE-2014-3517 affects OpenStack Nova versions prior to 2013.2.4, all 2014.x versions before 2014.1.2, and Juno prior to Juno-2.
What causes CVE-2014-3517 vulnerabilities in OpenStack Nova?
CVE-2014-3517 vulnerabilities are caused by timing differences that allow remote attackers to guess instance ID signatures.
Is CVE-2014-3517 a critical vulnerability for OpenStack users?
While CVE-2014-3517 is not classified as critical, it poses a security risk that should be addressed promptly by affected users.