CVE-2016-9185
published 2016-11-04CVE-2016-9185: In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration…
PriorityP421medium4.3CVSS 3.0
AVNACLPRLUINSUCLINAN
EPSS
1.54%
72.1th percentile
In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are =6.0.0 <=6.1.0, and ==7.0.0.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | heat | < heat 1:7.0.0-2 (bookworm) | heat 1:7.0.0-2 (bookworm) |
| openstack | heat | — | — |
| openstack | heat | — | — |
| openstack | heat | — | — |
| openstack | heat | — | — |
| openstack | heat | >= 0 < 1:7.0.0-2 | 1:7.0.0-2 |
| openstack | heat | >= 0 < 1:7.0.0-2 | 1:7.0.0-2 |
| openstack | heat | >= 0 < 1:7.0.0-2 | 1:7.0.0-2 |
| openstack | heat | >= 0 < 1:7.0.0-2 | 1:7.0.0-2 |
CVSS provenance
nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-249h-g975-9xj2: In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network confi
ghsa_unreviewed·2022-05-14
CVE-2016-9185 [MEDIUM] CWE-200 GHSA-249h-g975-9xj2: In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network confi
In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are =6.0.0 <=6.1.0, and ==7.0.0.
OSV
CVE-2016-9185: In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network confi
osv·2016-11-04·CVSS 4.3
CVE-2016-9185 [MEDIUM] CVE-2016-9185: In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network confi
In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are =6.0.0 <=6.1.0, and ==7.0.0.
Red Hat
openstack-heat: Template source URL allows network port scan
vendor_redhat·2016-11-03·CVSS 4.3
CVE-2016-9185 [MEDIUM] openstack-heat: Template source URL allows network port scan
openstack-heat: Template source URL allows network port scan
In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are =6.0.0 <=6.1.0, and ==7.0.0.
An information-leak vulnerability was found in the OpenStack Orchestration (heat) service. Launching a new stack with a local URL resulted in a detailed error message, allowing an authenticated user to conduct network discovery and reveal the details of internal network services.
Package: openstack-heat (Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)) - Will not fix
Package: openstack-heat (Red Hat Enterprise Linux OpenStack Platform 6 (Juno)) - Will not fix
Package: openstack-heat (Red Hat OpenStack Platfor
Debian
CVE-2016-9185: heat - In OpenStack Heat, by launching a new Heat stack with a local URL an authenticat...
vendor_debian·2016·CVSS 4.3
CVE-2016-9185 [MEDIUM] CVE-2016-9185: heat - In OpenStack Heat, by launching a new Heat stack with a local URL an authenticat...
In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are =6.0.0 <=6.1.0, and ==7.0.0.
Scope: local
bookworm: resolved (fixed in 1:7.0.0-2)
bullseye: resolved (fixed in 1:7.0.0-2)
forky: resolved (fixed in 1:7.0.0-2)
sid: resolved (fixed in 1:7.0.0-2)
trixie: resolved (fixed in 1:7.0.0-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9185 openstack-heat: Template source URL allows network port scan [openstack-rdo]
bugzilla·2016-11-06·CVSS 4.3
CVE-2016-9185 [MEDIUM] CVE-2016-9185 openstack-heat: Template source URL allows network port scan [openstack-rdo]
CVE-2016-9185 openstack-heat: Template source URL allows network port scan [openstack-rdo]
This as an RDO Project security tracking bug against openstack-heat. It was created
to ensure that one or more security vulnerabilities are fixed.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
[bug automatically created by: add-tracking-bugs]
Bugzilla
CVE-2016-9185 openstack-heat: Template source URL allows network port scan
bugzilla·2016-11-04·CVSS 4.3
CVE-2016-9185 [MEDIUM] CVE-2016-9185 openstack-heat: Template source URL allows network port scan
CVE-2016-9185 openstack-heat: Template source URL allows network port scan
A vulnerability was found in Heat. By launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration.
Upstream bug:
https://bugs.launchpad.net/ossa/+bug/1606500
Discussion:
Created openstack-heat tracking bugs for this issue:
Affects: fedora-all [bug 1391896]
---
Created openstack-heat tracking bugs for this issue:
Affects: openstack-rdo [bug 1392249]
---
This issue has been addressed in the following products:
Red Hat OpenStack Platform 8.0 (Liberty)
Via RHSA-2017:1456 https://access.redhat.com/errata/RHSA-2017:1456
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux OpenStack Platform 7.0 (Ki
Bugzilla
CVE-2016-9185 openstack-heat: Template source URL allows network port scan [fedora-all]
bugzilla·2016-11-04·CVSS 4.3
CVE-2016-9185 [MEDIUM] CVE-2016-9185 openstack-heat: Template source URL allows network port scan [fedora-all]
CVE-2016-9185 openstack-heat: Template source URL allows network port scan [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ve
http://www.securityfocus.com/bid/94205https://access.redhat.com/errata/RHSA-2017:1450https://access.redhat.com/errata/RHSA-2017:1456https://access.redhat.com/errata/RHSA-2017:1464https://bugs.launchpad.net/ossa/+bug/1606500http://www.securityfocus.com/bid/94205https://access.redhat.com/errata/RHSA-2017:1450https://access.redhat.com/errata/RHSA-2017:1456https://access.redhat.com/errata/RHSA-2017:1464https://bugs.launchpad.net/ossa/+bug/1606500
2016-11-04
Published