Vulnerabilities
Vulnerable Software
Openstack:  >> Heat  >> 2013.2  Security Vulnerabilities
OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list.
CVSS Score
3.5
EPSS Score
0.004
Published
2014-05-23
The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 does not properly enforce policy rules, which allows local in-instance users to bypass intended access restrictions and (1) create a stack via the CreateStack method or (2) update a stack via the UpdateStack method.
CVSS Score
4.0
EPSS Score
0.003
Published
2013-12-14
The ReST API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 allows remote authenticated users to bypass the tenant scoping restrictions via a modified tenant_id in the request path.
CVSS Score
4.0
EPSS Score
0.002
Published
2013-12-14


Contact Us

Shodan ® - All rights reserved