CVE-2014-3801: Infoleak
Published May 23, 2014
·Updated
OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list.
Affected Software
6 affected componentsFixes available
pip/openstack-heat<5.0.0a0
5.0.0a0
Openstack Heat=2013.2
Openstack Heat=2013.2.1
Openstack Heat=2013.2.2
Openstack Heat=2013.2.3
Openstack Heat=2014.1
Event History
May 23, 2014
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:55 PM
DescriptionSeverityWeaknessAffected Software
May 14, 2022
Advisory Published
04:01 AM
Frequently Asked Questions
1
What is the severity of CVE-2014-3801?
CVE-2014-3801 is considered a medium severity vulnerability that affects OpenStack Heat.
2
How do I fix CVE-2014-3801?
To fix CVE-2014-3801, update OpenStack Heat to version 5.0.0a0 or later.
3
Who is affected by CVE-2014-3801?
CVE-2014-3801 affects remote authenticated users of OpenStack Orchestration API (Heat) versions 2013.2 through 2014.1.
4
What does CVE-2014-3801 allow an attacker to do?
CVE-2014-3801 allows remote authenticated users to obtain the provider template URL through the resource-type-list.
5
When was CVE-2014-3801 disclosed?
CVE-2014-3801 was disclosed in 2014 as a vulnerability in OpenStack Heat.