CVE-2014-3801
published 2014-05-23CVE-2014-3801: OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote…
PriorityP415low3.5CVSS 2.0
AVNACMAuSCPINAN
EPSS
1.62%
73.4th percentile
OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | heat | < heat 2014.1-4 (bookworm) | heat 2014.1-4 (bookworm) |
| openstack | heat | — | — |
| openstack | heat | — | — |
| openstack | heat | — | — |
| openstack | heat | — | — |
| openstack | heat | — | — |
| openstack | heat | >= 0 < 2014.1-4 | 2014.1-4 |
| openstack | heat | >= 0 < 2014.1-4 | 2014.1-4 |
| openstack | heat | >= 0 < 2014.1-4 | 2014.1-4 |
| openstack | heat | >= 0 < 2014.1-4 | 2014.1-4 |
CVSS provenance
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
osv3.5LOW
vendor_debian3.5LOW
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
OpenStack Heat template URL information leakage
ghsa·2022-05-14
CVE-2014-3801 [LOW] CWE-200 OpenStack Heat template URL information leakage
OpenStack Heat template URL information leakage
OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list.
OSV
OpenStack Heat template URL information leakage
osv·2022-05-14
CVE-2014-3801 [LOW] OpenStack Heat template URL information leakage
OpenStack Heat template URL information leakage
OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list.
OSV
CVE-2014-3801: OpenStack Orchestration API (Heat) 2013
osv·2014-05-23·CVSS 3.5
CVE-2014-3801 [LOW] CVE-2014-3801: OpenStack Orchestration API (Heat) 2013
OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list.
Ubuntu
OpenStack Heat vulnerability
vendor_ubuntu·2014-06-18
CVE-2014-3801 OpenStack Heat vulnerability
Title: OpenStack Heat vulnerability
Summary: OpenStack Heat would expose sensitive information over the network.
Jason Dunsmore discovered that OpenStack heat did not properly restrict
access to template information. A remote authenticated attacker could
exploit this to see URL provider templates of other tenants for a limited
time.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
openstack-heat: authenticated information leak in Heat
vendor_redhat·2014-04-23·CVSS 3.5
CVE-2014-3801 [LOW] CWE-200 openstack-heat: authenticated information leak in Heat
openstack-heat: authenticated information leak in Heat
OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list.
It was discovered that a user could temporarily be able to see the URL of a provider template used in another tenant. If the template itself could be accessed, then additional information could be leaked that would otherwise not be visible.
Package: openstack-heat (Red Hat OpenStack Platform 3) - Will not fix
Debian
CVE-2014-3801: heat - OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when crea...
vendor_debian·2014·CVSS 3.5
CVE-2014-3801 [LOW] CVE-2014-3801: heat - OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when crea...
OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list.
Scope: local
bookworm: resolved (fixed in 2014.1-4)
bullseye: resolved (fixed in 2014.1-4)
forky: resolved (fixed in 2014.1-4)
sid: resolved (fixed in 2014.1-4)
trixie: resolved (fixed in 2014.1-4)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3801 openstack-heat: authenticated information leak in Heat
bugzilla·2014-05-21·CVSS 3.5
CVE-2014-3801 [LOW] CVE-2014-3801 openstack-heat: authenticated information leak in Heat
CVE-2014-3801 openstack-heat: authenticated information leak in Heat
Title: Heat template URL information leakage
Reporter: Jason Dunsmore (Rackspace)
Products: Heat
Versions: 2013.2 to 2013.2.3, and 2014.1
Description:
Jason Dunsmore from Rackspace reported a vulnerability in Heat. An
authenticated user may temporarily see the URL of a provider template
used in another tenant by listing heat resources types. This may result
in disclosure of additional information if the template itself can be
accessed. The URL disappears from the listing after a certain point in
the stack creation. All Heat setups are affected.
https://launchpad.net/bugs/1311223
http://seclists.org/oss-sec/2014/q2/338
Discussion:
Created openstack-heat tracking bugs for this issue:
Affects: fedora-all [bug 1099749]
Bugzilla
CVE-2014-3801 openstack-heat: authenticated information leak in Heat [fedora-all]
bugzilla·2014-05-21·CVSS 3.5
CVE-2014-3801 [LOW] CVE-2014-3801 openstack-heat: authenticated information leak in Heat [fedora-all]
CVE-2014-3801 openstack-heat: authenticated information leak in Heat [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multi
http://rhn.redhat.com/errata/RHSA-2014-1687.htmlhttp://www.openwall.com/lists/oss-security/2014/05/20/1http://www.openwall.com/lists/oss-security/2014/05/20/6http://www.securityfocus.com/bid/67505http://www.ubuntu.com/usn/USN-2249-1https://bugs.launchpad.net/heat/+bug/1311223http://rhn.redhat.com/errata/RHSA-2014-1687.htmlhttp://www.openwall.com/lists/oss-security/2014/05/20/1http://www.openwall.com/lists/oss-security/2014/05/20/6http://www.securityfocus.com/bid/67505http://www.ubuntu.com/usn/USN-2249-1https://bugs.launchpad.net/heat/+bug/1311223
2014-05-23
Published