cbcvebase.
CVE-2014-3801
published 2014-05-23

CVE-2014-3801: OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote…

PriorityP415low3.5CVSS 2.0
AVNACMAuSCPINAN
EPSS
1.62%
73.4th percentile
OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianheat< heat 2014.1-4 (bookworm)heat 2014.1-4 (bookworm)
openstackheat
openstackheat
openstackheat
openstackheat
openstackheat
openstackheat>= 0 < 2014.1-42014.1-4
openstackheat>= 0 < 2014.1-42014.1-4
openstackheat>= 0 < 2014.1-42014.1-4
openstackheat>= 0 < 2014.1-42014.1-4

CVSS provenance

nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
osv3.5LOW
vendor_debian3.5LOW
vendor_redhat3.5LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.