Openstack Heat vulnerabilities

7 known vulnerabilities affecting openstack/heat.

Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM6LOW1

Vulnerabilities

Page 1 of 1
CVE-2023-1625MEDIUMCVSS 5.0≥ 0, < 1:19.0.0-22023-09-24
CVE-2023-1625 [MEDIUM] CVE-2023-1625: An information leak was discovered in OpenStack heat An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.
osv
CVE-2017-2621MEDIUMCVSS 5.5fixed in 8.0.02018-07-27
CVE-2017-2621 [MEDIUM] CWE-552 CVE-2017-2621: An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 a An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.
nvdosv
CVE-2016-9185MEDIUMCVSS 4.3v5.0.3v6.0.0+2 more2016-11-04
CVE-2016-9185 [MEDIUM] CWE-200 CVE-2016-9185: In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are =6.0.0 <=6.1.0, and ==7.0.0.
nvdosv
CVE-2015-5295MEDIUMCVSS 5.4≥ 0, < 1:6.0.0~rc3-12016-01-20
CVE-2015-5295 [MEDIUM] CVE-2015-5295: The template-validate command in OpenStack Orchestration API (Heat) before 2015 The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template, as demonstrated by file:///dev/zero.
osv
CVE-2014-3801LOWCVSS 3.5v2013.2v2013.2.1+3 more2014-05-23
CVE-2014-3801 [LOW] CWE-200 CVE-2014-3801: OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list.
nvdosv
CVE-2013-6428MEDIUMCVSS 4.0≤ 2013.22013-12-14
CVE-2013-6428 [MEDIUM] CWE-264 CVE-2013-6428: The ReST API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehou The ReST API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 allows remote authenticated users to bypass the tenant scoping restrictions via a modified tenant_id in the request path.
nvdosv
CVE-2013-6426MEDIUMCVSS 4.0≤ 2013.22013-12-14
CVE-2013-6426 [MEDIUM] CWE-264 CVE-2013-6426: The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and I The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 does not properly enforce policy rules, which allows local in-instance users to bypass intended access restrictions and (1) create a stack via the CreateStack method or (2) update a stack via the UpdateStack method.
nvdosv