Comment 24 for bug 1325128

Revision history for this message
Grant Murphy (gmurphy) wrote : Re: nova metadata does not use a constant time compare for validating an HMAC token (CVE-2014-3517)

The original patch supplied no longer applies cleanly to master. I've tweaked it to the keystone version and back-ported to supported security levels.

Can we get these patches reviewed and approved? I would like to send the pre-OSSA out soon with a view to have a disclosure date of mid next week.