Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5295

Опубликовано: 19 янв. 2016
Источник: redhat
CVSS2: 6.8

Описание

The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template, as demonstrated by file:///dev/zero.

A vulnerability was discovered in the OpenStack Orchestration service (heat), where a specially formatted template could be used to trick the heat-engine service into opening a local file. Although the file contents are never disclosed to the end user, an OpenStack-authenticated attacker could use this flaw to cause a denial of service or determine whether a given file name is present on the server.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenStack Platform 8 (Liberty)openstack-heatAffected
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 6openstack-heatFixedRHSA-2016:044014.03.2016
Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7openstack-heatFixedRHSA-2016:044114.03.2016
Red Hat Enterprise Linux OpenStack Platform 6.0 (Juno) for RHEL 7openstack-heatFixedRHSA-2016:044214.03.2016
Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7openstack-heatFixedRHSA-2016:026618.02.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1298295openstack-heat: Vulnerability in Heat template validation leading to DoS

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.4
ubuntu
около 10 лет назад

The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template, as demonstrated by file:///dev/zero.

CVSS3: 5.4
nvd
около 10 лет назад

The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template, as demonstrated by file:///dev/zero.

CVSS3: 5.4
debian
около 10 лет назад

The template-validate command in OpenStack Orchestration API (Heat) be ...

CVSS3: 5.4
github
больше 3 лет назад

The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template, as demonstrated by file:///dev/zero.

6.8 Medium

CVSS2