First published: Fri Mar 24 2023(Updated: )
An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
pip/openstack-heat | <20.0.0 | 20.0.0 |
ubuntu/heat | <1:10.0.2-0ubuntu1.1 | 1:10.0.2-0ubuntu1.1 |
ubuntu/heat | <1:14.2.0-0ubuntu1.1 | 1:14.2.0-0ubuntu1.1 |
ubuntu/heat | <1:18.0.1-0ubuntu1.1 | 1:18.0.1-0ubuntu1.1 |
debian/heat | <=1:11.0.0-6<=1:15.0.0-4 | 1:19.0.0-3 1:21.0.0-4 |
redhat/openstack-heat | <22.0.0.0 | 22.0.0.0 |
openstack heat | ||
redhat openstack platform | =13.0 | |
redhat openstack platform | =16.1 | |
redhat openstack platform | =16.2 | |
redhat openstack platform | =17.0 |
https://github.com/openstack/heat/commit/1305a3152f75c6e62ec5094ea2bfc38f165204cf (20.0.0.0rc1)
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this information leak issue in OpenStack heat is CVE-2023-1625.
This vulnerability has a low impact on the confidentiality, integrity, and availability of the system.
The versions of OpenStack heat affected by this vulnerability are 1:10.0.2-0ubuntu1.1, 1:14.2.0-0ubuntu1.1, 1:18.0.1-0ubuntu1.1, 1:19.0.0-3, and 1:20.0.0-4.
A remote, authenticated attacker can exploit this vulnerability by using the 'stack show' command to reveal hidden parameters.
You can find more information about this vulnerability at the following references: [Link 1](https://review.opendev.org/c/openstack/heat/+/868166), [Link 2](https://github.com/openstack/heat/commit/a49526c278e52823080c7f3fcb72785b93fd4dcb), [Link 3](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2181623).