Lucene search

K
githubGitHub Advisory DatabaseGHSA-86QJ-4H55-FVPW
HistoryMay 14, 2022 - 4:01 a.m.

OpenStack Heat template URL information leakage

2022-05-1404:01:58
CWE-200
GitHub Advisory Database
github.com
3
openstack
heat
template
url
information
leakage
orchestration api
remote
authenticated
users
provider
resource-type-list
software

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

AI Score

6.7

Confidence

Low

EPSS

0.002

Percentile

60.2%

OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list.

Affected configurations

Vulners
Node
openstackheatRange<5.0.0a0

CVSS2

3.5

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:N/A:N

AI Score

6.7

Confidence

Low

EPSS

0.002

Percentile

60.2%