Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-6426

Опубликовано: 14 дек. 2013
Источник: ubuntu
Приоритет: medium
CVSS2: 4

Описание

The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 does not properly enforce policy rules, which allows local in-instance users to bypass intended access restrictions and (1) create a stack via the CreateStack method or (2) update a stack via the UpdateStack method.

РелизСтатусПримечание
devel

not-affected

2014.1~rc1-0ubuntu1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [2014.1~rc1-0ubuntu1]]
lucid

DNE

precise

DNE

quantal

DNE

raring

DNE

saucy

ignored

end of life
trusty

not-affected

2014.1~rc1-0ubuntu1
trusty/esm

DNE

trusty was not-affected [2014.1~rc1-0ubuntu1]
upstream

released

2014.1.rc1

Показывать по

4 Medium

CVSS2

Связанные уязвимости

redhat
около 12 лет назад

The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 does not properly enforce policy rules, which allows local in-instance users to bypass intended access restrictions and (1) create a stack via the CreateStack method or (2) update a stack via the UpdateStack method.

nvd
около 12 лет назад

The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 does not properly enforce policy rules, which allows local in-instance users to bypass intended access restrictions and (1) create a stack via the CreateStack method or (2) update a stack via the UpdateStack method.

debian
около 12 лет назад

The cloudformation-compatible API in OpenStack Orchestration API (Heat ...

github
больше 3 лет назад

The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 does not properly enforce policy rules, which allows local in-instance users to bypass intended access restrictions and (1) create a stack via the CreateStack method or (2) update a stack via the UpdateStack method.

4 Medium

CVSS2