Skip to content

OpenStack Nova Router metadata queries are not restricted by tenant

Moderate severity GitHub Reviewed Published May 17, 2022 to the GitHub Advisory Database • Updated May 14, 2024

Package

pip nova (pip)

Affected versions

< 12.0.0a0

Patched versions

12.0.0a0

Description

Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive metadata by spoofing the device ID that is bound to a port, which is not properly handled by (1) api/metadata/handler.py in Nova and (2) the neutron-metadata-agent (agent/metadata/agent.py) in Neutron.

References

Published by the National Vulnerability Database Jan 7, 2014
Published to the GitHub Advisory Database May 17, 2022
Reviewed May 14, 2024
Last updated May 14, 2024

Severity

Moderate

EPSS score

0.406%
(74th percentile)

Weaknesses

CVE ID

CVE-2013-6419

GHSA ID

GHSA-22w9-j288-8p9w

Source code

Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.