Comment 18 for bug 1325128

Revision history for this message
Grant Murphy (gmurphy) wrote : Re: nova metadata does not use a constant time compare for validating an HMAC token (CVE-2014-3517)

CVE assigned using the following impact description:

Title: Use of non-constant time comparison operation
Reporter: Alex Gaynor (Rackspace)
Products: Nova
Versions: Up to 2013.2.3, and 2014.1 to 2014.1.1

Alex Gaynor from Rackspace reported a timing attack vulnerability in Nova.
By analyzing response times to requests for instance metadata, an attacker
may be able to guess a valid instance ID signature. This could allow access
to important configuration details of another instance. Only setups
configured to proxy metadata requests via Neutron are affected.

Disclosure day/date schedule TBD. In preparation can we please get a definitive +1 / +2 on the patch from nova-coresec ?