The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| tripleo-heat-templates(PyPI) | 0 | 0.8.10 | N/A |
CVSS Metrics