VYPR
Moderate severityNVD Advisory· Published Aug 7, 2014· Updated May 6, 2026

CVE-2014-3517

CVE-2014-3517

Description

api/metadata/handler.py in OpenStack Compute (Nova) before 2013.2.4, 2014.x before 2014.1.2, and Juno before Juno-2, when proxying metadata requests through Neutron, makes it easier for remote attackers to guess instance ID signatures via a brute-force attack that relies on timing differences in responses to instance metadata requests.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
novaPyPI
< 2013.2.42013.2.4
novaPyPI
>= 2014.0.0, < 2014.1.22014.1.2

Affected products

2
  • OpenStack/Nova2 versions
    cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:openstack:nova:*:*:*:*:*:*:*:*range: >=2013.2,<=2013.2.4
    • cpe:2.3:a:openstack:nova:2014.2.0:milestone1:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.