Описание
In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0, and ==7.0.0.
An information-leak vulnerability was found in the OpenStack Orchestration (heat) service. Launching a new stack with a local URL resulted in a detailed error message, allowing an authenticated user to conduct network discovery and reveal the details of internal network services.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse) | openstack-heat | Will not fix | ||
| Red Hat Enterprise Linux OpenStack Platform 6 (Juno) | openstack-heat | Will not fix | ||
| Red Hat OpenStack Platform 10 (Newton) | openstack-heat | Not affected | ||
| Red Hat Enterprise Linux OpenStack Platform 7.0 (Kilo) for RHEL 7 | openstack-heat | Fixed | RHSA-2017:1450 | 14.06.2017 |
| Red Hat OpenStack Platform 8.0 (Liberty) | openstack-heat | Fixed | RHSA-2017:1456 | 14.06.2017 |
| Red Hat OpenStack Platform 9.0 (Mitaka) | openstack-heat | Fixed | RHSA-2017:1464 | 14.06.2017 |
Показывать по
Дополнительная информация
Статус:
EPSS
3.5 Low
CVSS3
2.3 Low
CVSS2
Связанные уязвимости
In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0, and ==7.0.0.
In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0, and ==7.0.0.
In OpenStack Heat, by launching a new Heat stack with a local URL an a ...
In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0, and ==7.0.0.
EPSS
3.5 Low
CVSS3
2.3 Low
CVSS2