VDB
KO
MEDIUM

GHSA-22w9-j288-8p9w

OpenStack Nova Router metadata queries are not restricted by tenant

Details

Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive metadata by spoofing the device ID that is bound to a port, which is not properly handled by (1) api/metadata/handler.py in Nova and (2) the neutron-metadata-agent (`agent/metadata/agent.py`) in Neutron.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / nova
Introduced in: 0 Fixed in: 12.0.0a0
Fix pip install --upgrade 'nova>=12.0.0a0'

References