CVE-2015-5303

HIGH

TripleO Heat templates - Open Redirect

Title source: llm

Description

The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.

Scores

CVSS v3 7.5
EPSS 0.0033
EPSS Percentile 55.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Classification

CWE
CWE-254
Status draft

Affected Products (2)

openstack/tripleo_heat_templates
pypi/tripleo-heat-templates < 0.8.10PyPI

Timeline

Published Apr 11, 2016
Tracked Since Feb 18, 2026