CVE-2014-3801

Publication date 23 May 2014

Last updated 24 July 2024


Ubuntu priority

OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list.

Status

Package Ubuntu Release Status
heat 14.04 LTS trusty
Fixed 2014.1-0ubuntu1.1
13.10 saucy Ignored end of life
12.04 LTS precise Not in release
10.04 LTS lucid Not in release

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
heat

References

Related Ubuntu Security Notices (USN)

    • USN-2249-1
    • OpenStack Heat vulnerability
    • 18 June 2014

Other references