PT-2016-7685 · Openstack · Openstack Heat
Tom Patzig
·
Published
2016-11-04
·
Updated
2018-01-05
·
CVE-2016-9185
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OpenStack Heat versions prior to 5.0.4
OpenStack Heat versions 6.0.0 through 6.1.0
OpenStack Heat version 7.0.0
Description
The issue allows an authenticated user to conduct network discovery, potentially revealing internal network configuration, by launching a new Heat stack with a local URL.
Recommendations
For OpenStack Heat versions prior to 5.0.4, update to version 5.0.4 or later.
For OpenStack Heat versions 6.0.0 through 6.1.0, update to version 6.1.1 or later.
For OpenStack Heat version 7.0.0, update to a version later than 7.0.0.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openstack Heat