Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Tom Patzig

Researcher fromSAP
#52169of 53,723
4.3Total CVSS
Vulnerabilities · 1
PT-2016-7685
4.3
2016-11-04
Openstack · Openstack Heat · CVE-2016-9185
**Name of the Vulnerable Software and Affected Versions** OpenStack Heat versions prior to 5.0.4 OpenStack Heat versions 6.0.0 through 6.1.0 OpenStack Heat version 7.0.0 **Description** The issue allows an authenticated user to conduct network discovery, potentially revealing internal network configuration, by launching a new Heat stack with a local URL. **Recommendations** For OpenStack Heat versions prior to 5.0.4, update to version 5.0.4 or later. For OpenStack Heat versions 6.0.0 through 6.1.0, update to version 6.1.1 or later. For OpenStack Heat version 7.0.0, update to a version later than 7.0.0.