First published: Fri Nov 04 2016(Updated: )
In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0, and ==7.0.0.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
openstack heat | =5.0.3 | |
openstack heat | =6.0.0 | |
openstack heat | =6.1.0 | |
openstack heat | =7.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9185 is considered a moderate severity vulnerability due to its potential for network configuration disclosure.
CVE-2016-9185 affects OpenStack Heat versions 5.0.3, 6.0.0, 6.1.0, and 7.0.0.
To fix CVE-2016-9185, upgrade OpenStack Heat to a version later than 6.1.0 or switch to the most recent supported release.
Exploiting CVE-2016-9185 allows authenticated users to conduct network discovery, potentially exposing internal network configurations.
Organizations using the affected versions of OpenStack Heat may be at risk if they allow authenticated users access to launch new stacks.