api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through Neutron, makes it easier for remote attackers to guess instance ID signatures via a brute-force attack that relies on timing differences in responses to instance metadata requests.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade nova | Jul 30, 2024 | Aug 7, 2014 |
| Oracle Solaris | — | Upgrade cloud/openstack/nova to version 0.2013.2.3-0.175.2.3.0.4.0 on Solaris 11.2Upgrade cloud/openstack/glance to version 0.2013.2.3-0.175.2.3.0.4.0 on Solaris 11.2Upgrade cloud/openstack/cinder to version 0.2013.2.3-0.175.2.3.0.4.0 on Solaris 11.2 | May 29, 2017 | Aug 7, 2014 |
| Ubuntu | — | Upgrade python-nova | Nov 8, 2024 | Aug 7, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub