-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stemmed from Heat template parameters with a default value of 'unset' for NeutronMetadataProxySharedSecret. The commit diff shows this default was removed in multiple YAML files (overcloud.yaml, puppet/controller.yaml, puppet/compute.yaml). These parameter definitions (not traditional functions) created a predictable secret, violating security best practices for secret management. The high confidence comes from direct evidence in patch diffs and CVE description linking the default value to the exploit.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| tripleo-heat-templates | pip | < 0.8.10 | 0.8.10 |
Ongoing coverage of React2Shell