Safety vulnerability ID: 67989
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive metadata by spoofing the device ID that is bound to a port, which is not properly handled by (1) api/metadata/handler.py in Nova and (2) the neutron-metadata-agent (agent/metadata/agent.py) in Neutron.
Latest version: 30.0.0
Cloud computing fabric controller
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application