ossa/ossa/OSSA-2013-034.yaml

57 lines
1.2 KiB
YAML

date: 2013-12-11
id: OSSA-2013-034
title: 'Heat CFN policy rules not all enforced'
description: 'Steven Hardy from Red Hat reported a vulnerability in Heat''s default
API policy enforcement. By calling the CreateStack or UpdateStack methods, an in-instance
user may be able to create or update a stack in violation of the default policy.
Only setups using Heat''s cloudformation-compatible API are affected.'
reference: http://lists.openstack.org/pipermail/openstack-announce/2013-December/000170.html
affected-products:
- product: heat
version: All supported releases
vulnerabilities:
- cve-id: CVE-2013-6426
impact-assessment:
source: 'Red Hat Product Security'
rating: moderate
assessment:
type: CVSS2
score: 4.0
detail: AV:N/AC:L/Au:S/C:N/I:P/A:N
classification:
source: 'Red Hat Product Security'
type: CWE
detail: TODO
reporters:
- name: 'Steven Hardy'
affiliation: 'Red Hat'
reported:
- CVE-2013-6426
issues:
links:
- https://launchpad.net/bugs/1256049
type: launchpad
reviews:
icehouse:
- https://review.openstack.org/#/c/61452
havana:
- https://review.openstack.org/#/c/61454
type: gerrit