First published: Fri Oct 16 2015(Updated: )
Steven Hardy reports: Currently we don't set the NeutronMetadataProxySharedSecret, (which according to the description in the neutron docs exists to prevent spoofing) - thus is remains at it's bad default value of "unset". I assume this has the potential for security impact given that if it's predictable I guess spoofing metadata requests then becomes possible, but not being a Neutron expert I'm not sure of how serious an issue this may be.
Affected Software | Affected Version | How to fix |
---|---|---|
Neutron |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-1272297 is considered high due to the potential for security impacts from the unset NeutronMetadataProxySharedSecret.
To fix REDHAT-BUG-1272297, set the NeutronMetadataProxySharedSecret to a secure, non-default value as per neutron documentation.
The potential impact of REDHAT-BUG-1272297 includes vulnerabilities to spoofing attacks due to the unset shared secret.
REDHAT-BUG-1272297 affects OpenStack Neutron, particularly in configurations lacking the NeutronMetadataProxySharedSecret.
REDHAT-BUG-1272297 was reported by Steven Hardy.