CVE-2023-1625: Information leak in api
An information leak was discovered in openstack heat. https://review.opendev.org/c/openstack/heat/+/868166 https://github.com/openstack/heat/commit/a49526c278e52823080c7f3fcb72785b93fd4dcb
The get stack environment API doesn't mask hidden parameter values. A malicious system user can get sensitive data by this API even though encryptparametersandproperties option is set to true. All VMs deployed by this heat template may be compromised.
Other sources
An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.
— Ubuntu
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this information leak issue in OpenStack heat?
The vulnerability ID for this information leak issue in OpenStack heat is CVE-2023-1625.
What is the impact of this vulnerability?
This vulnerability has a low impact on the confidentiality, integrity, and availability of the system.
Which version of OpenStack heat is affected by this vulnerability?
The versions of OpenStack heat affected by this vulnerability are 1:10.0.2-0ubuntu1.1, 1:14.2.0-0ubuntu1.1, 1:18.0.1-0ubuntu1.1, 1:19.0.0-3, and 1:20.0.0-4.
How can a remote, authenticated attacker exploit this vulnerability?
A remote, authenticated attacker can exploit this vulnerability by using the 'stack show' command to reveal hidden parameters.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following references: [Link 1](https://review.opendev.org/c/openstack/heat/+/868166), [Link 2](https://github.com/openstack/heat/commit/a49526c278e52823080c7f3fcb72785b93fd4dcb), [Link 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2181623).