REDHAT-BUG-1272297: Medium severity Openstack Neutron vulnerability
Steven Hardy reports: Currently we don't set the NeutronMetadataProxySharedSecret, (which according to the description in the neutron docs exists to prevent spoofing) - thus is remains at it's bad default value of "unset".
I assume this has the potential for security impact given that if it's predictable I guess spoofing metadata requests then becomes possible, but not being a Neutron expert I'm not sure of how serious an issue this may be.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1272297?
The severity of REDHAT-BUG-1272297 is considered high due to the potential for security impacts from the unset NeutronMetadataProxySharedSecret.
How do I fix REDHAT-BUG-1272297?
To fix REDHAT-BUG-1272297, set the NeutronMetadataProxySharedSecret to a secure, non-default value as per neutron documentation.
What is the potential impact of REDHAT-BUG-1272297?
The potential impact of REDHAT-BUG-1272297 includes vulnerabilities to spoofing attacks due to the unset shared secret.
Which software is affected by REDHAT-BUG-1272297?
REDHAT-BUG-1272297 affects OpenStack Neutron, particularly in configurations lacking the NeutronMetadataProxySharedSecret.
Who reported REDHAT-BUG-1272297?
REDHAT-BUG-1272297 was reported by Steven Hardy.