CVE-2014-3801
OpenStack Heat template URL information leakage
EPSS 0.43%
Description
OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list.
How to fix CVE-2014-3801
To remediate CVE-2014-3801, upgrade the affected package to a fixed version below.
- Debian/heat—upgrade to 2014.1-4 or later
- PyPI/openstack-heat—upgrade to 5.0.0a0 or later
Is CVE-2014-3801 being exploited?
Low — EPSS is 0.4%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2014.1-4
- from 0, < 5.0.0a0