PT-2013-6043 · Openstack · Openstack Orchestration Api
Shardy
+1
·
Published
2013-12-11
·
Updated
2014-03-06
·
CVE-2013-6428
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
OpenStack Orchestration API (Heat) versions before Havana 2013.2.1
OpenStack Orchestration API (Heat) versions before Icehouse icehouse-2
Description
The issue allows remote authenticated users to bypass tenant scoping restrictions. This is achieved by modifying the
tenant id in the request path of the ReST API.Recommendations
For versions before Havana 2013.2.1, update to Havana 2013.2.1 or later to resolve the issue.
For versions before Icehouse icehouse-2, update to Icehouse icehouse-2 or later to resolve the issue.
As a temporary workaround, consider restricting access to the ReST API to minimize the risk of exploitation.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openstack Orchestration Api