Junglewise Threat Intelligence

CVE-2015-5303: PYSEC-2016-35 - The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack

CVE-2015-5303 · Severity: low · CVSS 3 · Published 2016-04-11

Technologies: tripleo-heat-templates (PyPI). Vendors: PyPI.

Executive brief

The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.

Affected products

  • PyPI tripleo-heat-templates

Related threats