Candidate: CVE-2015-5303 PublicDate: 2016-04-11 21:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-5303 Description: The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter. Ubuntu-Description: Notes: Mitigation: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851396 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_tripleo-heat-templates: upstream_tripleo-heat-templates: released (5.2.0-1) trusty_tripleo-heat-templates: ignored (out of standard support) trusty/esm_tripleo-heat-templates: DNE xenial_tripleo-heat-templates: ignored (out of standard support) bionic_tripleo-heat-templates: not-affected (5.2.0-1) focal_tripleo-heat-templates: DNE hirsute_tripleo-heat-templates: DNE impish_tripleo-heat-templates: DNE jammy_tripleo-heat-templates: DNE devel_tripleo-heat-templates: DNE