CVE-2016-9185: Infoleak
A vulnerability was found in Heat. By launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration.
Upstream bug:
https://bugs.launchpad.net/ossa/+bug/1606500
Other sources
In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0, and ==7.0.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9185?
CVE-2016-9185 is considered a moderate severity vulnerability due to its potential for network configuration disclosure.
What systems are affected by CVE-2016-9185?
CVE-2016-9185 affects OpenStack Heat versions 5.0.3, 6.0.0, 6.1.0, and 7.0.0.
How do I fix CVE-2016-9185?
To fix CVE-2016-9185, upgrade OpenStack Heat to a version later than 6.1.0 or switch to the most recent supported release.
What is the impact of exploiting CVE-2016-9185?
Exploiting CVE-2016-9185 allows authenticated users to conduct network discovery, potentially exposing internal network configurations.
Who is at risk from CVE-2016-9185?
Organizations using the affected versions of OpenStack Heat may be at risk if they allow authenticated users access to launch new stacks.