Back

MEDIUM

Nova: Metadata queries from Neutron to Nova are not restricted by tenant

Published Jan 7, 2014

Description

Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive metadata by spoofing the device ID that is bound to a port, which is not properly handled by (1) api/metadata/handler.py in Nova and (2) the neutron-metadata-agent (agent/metadata/agent.py) in Neutron.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 7, 2014
Updated Aug 6, 2024
Reserved Nov 4, 2013
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Dec 11, 2013
GHSA-22W9-J288-8P9W