CVE-2013-6426
published 2013-12-14CVE-2013-6426: The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 does not properly enforce policy…
PriorityP419medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
1.03%
60.2th percentile
The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 does not properly enforce policy rules, which allows local in-instance users to bypass intended access restrictions and (1) create a stack via the CreateStack method or (2) update a stack via the UpdateStack method.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | heat | < heat 2013.2.1-1 (bookworm) | heat 2013.2.1-1 (bookworm) |
| openstack | heat | <= 2013.2 | — |
| openstack | heat | >= 0 < 2013.2.1-1 | 2013.2.1-1 |
| openstack | heat | >= 0 < 2013.2.1-1 | 2013.2.1-1 |
| openstack | heat | >= 0 < 2013.2.1-1 | 2013.2.1-1 |
| openstack | heat | >= 0 < 2013.2.1-1 | 2013.2.1-1 |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3m5x-89wr-x574: The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013
ghsa_unreviewed·2022-05-17
CVE-2013-6426 [MEDIUM] GHSA-3m5x-89wr-x574: The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013
The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 does not properly enforce policy rules, which allows local in-instance users to bypass intended access restrictions and (1) create a stack via the CreateStack method or (2) update a stack via the UpdateStack method.
OSV
CVE-2013-6426: The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013
osv·2013-12-14·CVSS 4.0
CVE-2013-6426 [MEDIUM] CVE-2013-6426: The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013
The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 does not properly enforce policy rules, which allows local in-instance users to bypass intended access restrictions and (1) create a stack via the CreateStack method or (2) update a stack via the UpdateStack method.
Red Hat
Heat: CFN policy rules not all enforced
vendor_redhat·2013-12-11·CVSS 4.0
CVE-2013-6426 [MEDIUM] Heat: CFN policy rules not all enforced
Heat: CFN policy rules not all enforced
The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 does not properly enforce policy rules, which allows local in-instance users to bypass intended access restrictions and (1) create a stack via the CreateStack method or (2) update a stack via the UpdateStack method.
Package: openstack-heat (Red Hat OpenStack Platform 3) - Will not fix
Debian
CVE-2013-6426: heat - The cloudformation-compatible API in OpenStack Orchestration API (Heat) before H...
vendor_debian·2013·CVSS 4.0
CVE-2013-6426 [MEDIUM] CVE-2013-6426: heat - The cloudformation-compatible API in OpenStack Orchestration API (Heat) before H...
The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 does not properly enforce policy rules, which allows local in-instance users to bypass intended access restrictions and (1) create a stack via the CreateStack method or (2) update a stack via the UpdateStack method.
Scope: local
bookworm: resolved (fixed in 2013.2.1-1)
bullseye: resolved (fixed in 2013.2.1-1)
forky: resolved (fixed in 2013.2.1-1)
sid: resolved (fixed in 2013.2.1-1)
trixie: resolved (fixed in 2013.2.1-1)
No detection rules found.
No public exploits indexed.
arXiv
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
arxiv_fulltext·2024-07-31
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
Microservice Vulnerability Analysis: A Literature Review with Empirical Insights
Raveen Kanishka Jayalath*
University of Adelaide, Australia
[email protected]
Hussain Ahmad* *Authors contributed equally to this work. Corresponding author.
University of Adelaide, Australia
[email protected]
Diksha Goel
CSIRO's Data61, Australia
[email protected]
3cmMuhammad Shuja Syed
3cmSLB, USA
[email protected]
Faheem Ullah
University of Adelaide, Australia
[email protected]
plain
## Abstract
Microservice architectures are revolutionizing both small businesses and large corporations, igniting a new era of innovation with their exceptional advantages in maintainability, reusability, and scalability. However, these benefits come w
Bugzilla
CVE-2013-6426 openstack-heat: OpenStack Heat: CFN policy rules not all enforced [fedora-19]
bugzilla·2014-06-23·CVSS 4.0
CVE-2013-6426 [MEDIUM] CVE-2013-6426 openstack-heat: OpenStack Heat: CFN policy rules not all enforced [fedora-19]
CVE-2013-6426 openstack-heat: OpenStack Heat: CFN policy rules not all enforced [fedora-19]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-19 tracking b
Bugzilla
CVE-2013-6426 OpenStack Heat: CFN policy rules not all enforced
bugzilla·2013-12-06·CVSS 4.0
CVE-2013-6426 [MEDIUM] CVE-2013-6426 OpenStack Heat: CFN policy rules not all enforced
CVE-2013-6426 OpenStack Heat: CFN policy rules not all enforced
Jeremy Stanley of the OpenStack Project reports:
Steven Hardy from Red Hat reported a vulnerability in Heat's default
API policy enforcement. By calling the CreateStack or UpdateStack
methods, an in-instance user may be able to create or update a stack
in violation of the default policy. Only setups using Heat's
cloudformation-compatible API are affected.
Discussion:
Acknowledgements:
Red Hat would like to thank Jeremy Stanley of the OpenStack Project for reporting this issue. Upstream acknowledges Steven Hardy of Red Hat as the original reporter.
---
Created attachment 833715
cve-2013-6426-master-icehouse.patch
---
Created attachment 833717
cve-2013-6426-stable-havana.patch
---
This issue has been addressed in foll
http://rhn.redhat.com/errata/RHSA-2014-0090.htmlhttp://www.openwall.com/lists/oss-security/2013/12/11/9http://www.securityfocus.com/bid/64243https://bugs.launchpad.net/heat/+bug/1256049https://exchange.xforce.ibmcloud.com/vulnerabilities/89658http://rhn.redhat.com/errata/RHSA-2014-0090.htmlhttp://www.openwall.com/lists/oss-security/2013/12/11/9http://www.securityfocus.com/bid/64243https://bugs.launchpad.net/heat/+bug/1256049https://exchange.xforce.ibmcloud.com/vulnerabilities/89658
2013-12-14
Published