CVE-2015-5303: High severity Openstack TripleO Heat templates vulnerability
Steven Hardy reports: Currently we don't set the NeutronMetadataProxySharedSecret, (which according to the description in the neutron docs exists to prevent spoofing) - thus is remains at it's bad default value of "unset".
I assume this has the potential for security impact given that if it's predictable I guess spoofing metadata requests then becomes possible, but not being a Neutron expert I'm not sure of how serious an issue this may be.
Other sources
The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/tripleo-heat-templatesto a version that resolves this vulnerability.Fixed in 0.8.10
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5303?
CVE-2015-5303 is classified as a moderate severity vulnerability.
How do I fix CVE-2015-5303?
To fix CVE-2015-5303, upgrade the 'tripleo-heat-templates' package to version 0.8.10 or higher.
What type of attack is possible with CVE-2015-5303?
CVE-2015-5303 allows remote attackers to spoof OpenStack Networking metadata requests.
What parameter is exploited in CVE-2015-5303?
The vulnerability exploits the default value of the NeutronMetadataProxySharedSecret parameter.
Which software is affected by CVE-2015-5303?
CVE-2015-5303 affects the OpenStack TripleO Heat Templates software.