CVE-2014-3801

OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.5 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:S/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
openstackheat
2013.2
openstackheat
2013.2.1
openstackheat
2013.2.2
openstackheat
2013.2.3
openstackheat
2014.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
heat
bookworm
1:19.0.0-3
fixed
bullseye
1:15.0.0-4
fixed
sid
1:23.0.0-3
fixed
trixie
1:23.0.0-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
heat
lucid
dne
precise
dne
saucy
ignored
trusty
Fixed 2014.1-0ubuntu1.1
released