Release date:
Updated on:
Affected Systems:
Openstack Heat 2014.1
Openstack Heat 2013.2-2013.2.3
Description:
--------------------------------------------------------------------------------
Bugtraq id: 67505
CVE (CAN) ID: CVE-2014-3801
OpenStack Heat is the main project of OpenStack Orchestration program. Multiple composite cloud applications are started using a compilation engine as a template in text format.
OpenStack Orchestration API (Heat) 2013.2-2013.2.3 and 2014.1 when using the provider template to create a template stack, authenticated attackers use the resource type list, attackers can exploit this vulnerability to obtain the URL of the provider template.
<* Source: Jason Dunsmore
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Openstack
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://wiki.openstack.org/wiki/Heat
Https://bugs.launchpad.net/heat/+bug/1311223
Install and deploy Openstack on Ubuntu 12.10
Ubuntu 12.04 OpenStack Swift single-node deployment Manual
OpenStack cloud computing quick start tutorial
Deploying OpenStack for enterprises: what should be done and what should not be done
This article permanently updates the link address: