OpenStack Heat Template URL Information Disclosure Vulnerability
BID:67505
Info
OpenStack Heat Template URL Information Disclosure Vulnerability
| Bugtraq ID: | 67505 |
| Class: | Design Error |
| CVE: |
CVE-2014-3801 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 22 2014 12:00AM |
| Updated: | Jun 20 2014 12:04AM |
| Credit: | Jason Dunsmore |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
OpenStack Heat Template URL Information Disclosure Vulnerability
OpenStack Heat is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may aid in launching further attacks.
OpenStack Heat versions 2013.2 through 2013.2.3, and 2014.1 are vulnerable.
OpenStack Heat is prone to an information-disclosure vulnerability.
Attackers can exploit this issue to obtain sensitive information that may aid in launching further attacks.
OpenStack Heat versions 2013.2 through 2013.2.3, and 2014.1 are vulnerable.
Exploit / POC
OpenStack Heat Template URL Information Disclosure Vulnerability
An attacker can exploit this issue using a web browser.
An attacker can exploit this issue using a web browser.
Solution / Fix
OpenStack Heat Template URL Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
OpenStack Heat Template URL Information Disclosure Vulnerability
References:
References: