REDHAT-BUG-2258810: Medium severity openstack heat vulnerability
An incomplete fix for CVE-2023-1625 in openstack-heat was discovered. Some sensitive information may still be disclosed through openstack stack abandon command even with the hidden feature set to True and CVE-2023-1625 fix applied.
References:
https://storyboard.openstack.org/#!/story/2011007
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2258810?
The severity of REDHAT-BUG-2258810 is high due to potential disclosure of sensitive information.
How do I fix REDHAT-BUG-2258810?
To fix REDHAT-BUG-2258810, apply the latest patch or update for OpenStack Heat provided by your distribution.
What version of OpenStack Heat is affected by REDHAT-BUG-2258810?
All versions of OpenStack Heat that do not have the fix for CVE-2023-1625 are affected by REDHAT-BUG-2258810.
Is any data at risk with REDHAT-BUG-2258810?
Yes, sensitive data may be at risk of disclosure when the openstack stack abandon command is executed.
What should I do if I cannot update OpenStack Heat regarding REDHAT-BUG-2258810?
If you cannot update OpenStack Heat, consider temporarily disabling the functionality that uses the stack abandon command until a fix can be applied.