Severity
5.0MEDIUM
EPSS
0.1%
top 64.63%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 24
Latest updateDec 24

Description

An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:LExploitability: 3.1 | Impact: 3.7

Affected Packages3 packages

PyPIopenstack-heat< 20.0.0
NVDredhat/openstack_platform4 versions+3
Debianheat< 1:19.0.0-2+2

Patches

🔴Vulnerability Details

6
OSV
f2fs: compress: fix to call f2fs_wait_on_page_writeback() in f2fs_write_raw_pages()2025-12-24
GHSA
openstack-heat may disclose sensitive information2024-08-02
CVEList
Information leak in api2023-09-24
OSV
OpenStack Heat information leak vulnerability2023-09-24
GHSA
OpenStack Heat information leak vulnerability2023-09-24

📋Vendor Advisories

5
Red Hat
kernel: f2fs: compress: fix to call f2fs_wait_on_page_writeback() in f2fs_write_raw_pages()2025-12-24
Red Hat
openstack-heat: Incomplete fix for CVE-2023-16252024-07-31
Ubuntu
OpenStack Heat vulnerability2023-08-16
Red Hat
openstack-heat: information leak in API2023-01-27
Debian
CVE-2023-1625: heat - An information leak was discovered in OpenStack heat. This issue could allow a r...2023
CVE-2023-1625 (MEDIUM CVSS 5) | An information leak was discovered | cvebase.io