Comment 8 for bug 1479385

Revision history for this message
Stuart McLaren (stuart-mclaren) wrote :

There is a previous bug/patch for this:

https://review.openstack.org/#/c/195820

but I'm not sure if the security aspect of it was covered.

From my -- fairly limited -- understanding of metadefs it does seem like there is a vulnerability here: a DOS of the metadefs API.