CVE-2013-6428
published 2013-12-14CVE-2013-6428: The ReST API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 allows remote authenticated users to bypass the tenant…
PriorityP423medium4CVSS 2.0
AVNACLAuSCNIPAN
EPSS
1.74%
75.4th percentile
The ReST API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 allows remote authenticated users to bypass the tenant scoping restrictions via a modified tenant_id in the request path.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | heat | < heat 2013.2.1-1 (bookworm) | heat 2013.2.1-1 (bookworm) |
| openstack | heat | <= 2013.2 | — |
| openstack | heat | >= 0 < 2013.2.1-1 | 2013.2.1-1 |
| openstack | heat | >= 0 < 2013.2.1-1 | 2013.2.1-1 |
| openstack | heat | >= 0 < 2013.2.1-1 | 2013.2.1-1 |
| openstack | heat | >= 0 < 2013.2.1-1 | 2013.2.1-1 |
CVSS provenance
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
osv4.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Heat: ReST API doesn't respect tenant scoping
vendor_redhat·2013-12-11·CVSS 4.0
CVE-2013-6428 [MEDIUM] Heat: ReST API doesn't respect tenant scoping
Heat: ReST API doesn't respect tenant scoping
The ReST API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 allows remote authenticated users to bypass the tenant scoping restrictions via a modified tenant_id in the request path.
Package: openstack-heat (Red Hat OpenStack Platform 3) - Will not fix
Debian
CVE-2013-6428: heat - The ReST API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Ic...
vendor_debian·2013·CVSS 4.0
CVE-2013-6428 [MEDIUM] CVE-2013-6428: heat - The ReST API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Ic...
The ReST API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 allows remote authenticated users to bypass the tenant scoping restrictions via a modified tenant_id in the request path.
Scope: local
bookworm: resolved (fixed in 2013.2.1-1)
bullseye: resolved (fixed in 2013.2.1-1)
forky: resolved (fixed in 2013.2.1-1)
sid: resolved (fixed in 2013.2.1-1)
trixie: resolved (fixed in 2013.2.1-1)
GHSA
GHSA-xrx4-52w3-mpjx: The ReST API in OpenStack Orchestration API (Heat) before Havana 2013
ghsa_unreviewed·2022-05-17
CVE-2013-6428 [MEDIUM] GHSA-xrx4-52w3-mpjx: The ReST API in OpenStack Orchestration API (Heat) before Havana 2013
The ReST API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 allows remote authenticated users to bypass the tenant scoping restrictions via a modified tenant_id in the request path.
OSV
CVE-2013-6428: The ReST API in OpenStack Orchestration API (Heat) before Havana 2013
osv·2013-12-14·CVSS 4.0
CVE-2013-6428 [MEDIUM] CVE-2013-6428: The ReST API in OpenStack Orchestration API (Heat) before Havana 2013
The ReST API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 allows remote authenticated users to bypass the tenant scoping restrictions via a modified tenant_id in the request path.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-6428 openstack-heat: OpenStack Heat: ReST API doesn't respect tenant scoping [fedora-19]
bugzilla·2014-06-23·CVSS 4.0
CVE-2013-6428 [MEDIUM] CVE-2013-6428 openstack-heat: OpenStack Heat: ReST API doesn't respect tenant scoping [fedora-19]
CVE-2013-6428 openstack-heat: OpenStack Heat: ReST API doesn't respect tenant scoping [fedora-19]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-19 trac
Bugzilla
CVE-2013-6428 OpenStack Heat: ReST API doesn't respect tenant scoping
bugzilla·2013-12-06·CVSS 4.0
CVE-2013-6428 [MEDIUM] CVE-2013-6428 OpenStack Heat: ReST API doesn't respect tenant scoping
CVE-2013-6428 OpenStack Heat: ReST API doesn't respect tenant scoping
Jeremy Stanley of the OpenStack Project reports:
Steven Hardy from Red Hat reported a vulnerability in the Heat ReST
API. By changing the request path, an authenticated client may
override their tenant scope resulting in privilege escalation. Only
setups exposing the Heat orchestration ReST interface are affected.
Discussion:
Acknowledgements:
Red Hat would like to thank Jeremy Stanley of the OpenStack Project for reporting this issue. Upstream acknowledges Steven Hardy of Red Hat as the original reporter.
---
Created attachment 833716
cve-2013-6428-master-icehouse.patch
---
Created attachment 833718
cve-2013-6428-stable-havana.patch
---
This issue has been addressed in following products:
OpenStack 4 for RHE
2013-12-14
Published