CVE-2015-5303: Openstack Tripleo Heat Templates

High severity, CVSS 7.5. EPSS: 1.7% chance of exploitation in the next 30 days.

The TripleO Heat templates (tripleo-heat-templates), when deployed via the commandline interface, allow remote attackers to spoof OpenStack Networking metadata requests by leveraging knowledge of the default value of the NeutronMetadataProxySharedSecret parameter.

Affected products

  • Openstack Tripleo Heat Templates: any version

Published 2016-04-11. Last modified 2026-06-17.