[PKG-Openstack-devel] Bug#843232: heat: CVE-2016-9185: template source URL allows network port scan

Salvatore Bonaccorso carnil at debian.org
Sat Nov 5 10:52:05 UTC 2016


Source: heat
Version: 1:7.0.0-1
Severity: grave
Tags: security upstream patch
Forwarded: https://bugs.launchpad.net/ossa/+bug/1606500

Hi,

the following vulnerability was published for heat.

CVE-2016-9185[0]:
| In OpenStack Heat, by launching a new Heat stack with a local URL an
| authenticated user may conduct network discovery revealing internal
| network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0,
| and ==7.0.0.

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2016-9185
[1] https://bugs.launchpad.net/ossa/+bug/1606500

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore



More information about the Openstack-devel mailing list