Home page logo
/

oss-sec logo oss-sec mailing list archives

[OSSA 2013-035] Heat ReST API doesn't respect tenant scoping (CVE-2013-6428)
From: Jeremy Stanley <jeremy () openstack org>
Date: Wed, 11 Dec 2013 15:52:50 +0000

OpenStack Security Advisory: 2013-035
CVE: CVE-2013-6428
Date: December 11, 2013
Title: Heat ReST API doesn't respect tenant scoping
Reporter: Steven Hardy (Red Hat)
Products: Heat
Affects: All supported releases

Description:
Steven Hardy from Red Hat reported a vulnerability in the Heat ReST
API. By changing the request path, an authenticated client may
override their tenant scope resulting in privilege escalation. Only
setups exposing the Heat orchestration ReST interface are affected.

Icehouse (development branch) fix:
https://review.openstack.org/61455

Havana fix:
https://review.openstack.org/61456

Notes:
This fix will be included in the icehouse-2 development milestone
and in a future 2013.2.1 release.

References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6428
https://launchpad.net/bugs/1256983

-- 
Jeremy Stanley
OpenStack Vulnerability Management Team

Attachment: signature.asc
Description: Digital signature


  By Date           By Thread  

Current thread:
  • [OSSA 2013-035] Heat ReST API doesn't respect tenant scoping (CVE-2013-6428) Jeremy Stanley (Dec 11)
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]