ossa/ossa/OSSA-2013-035.yaml

57 lines
1.2 KiB
YAML

date: 2013-12-11
id: OSSA-2013-035
title: 'Heat ReST API doesn''t respect tenant scoping'
description: 'Steven Hardy from Red Hat reported a vulnerability in the Heat ReST
API. By changing the request path, an authenticated client may override their tenant
scope resulting in privilege escalation. Only setups exposing the Heat orchestration
ReST interface are affected.'
reference: http://lists.openstack.org/pipermail/openstack-announce/2013-December/000172.html
affected-products:
- product: heat
version: All supported releases
vulnerabilities:
- cve-id: CVE-2013-6428
impact-assessment:
source: 'Red Hat Product Security'
rating: moderate
assessment:
type: CVSS2
score: 4.0
detail: AV:N/AC:L/Au:S/C:N/I:P/A:N
classification:
source: 'Red Hat Product Security'
type: CWE
detail: TODO
reporters:
- name: 'Steven Hardy'
affiliation: 'Red Hat'
reported:
- CVE-2013-6428
issues:
links:
- https://launchpad.net/bugs/1256983
type: launchpad
reviews:
icehouse:
- https://review.openstack.org/#/c/61455
havana:
- https://review.openstack.org/#/c/61456
type: gerrit