UBUNTU-CVE-2013-6426
Dashboard / Vulnerabilities / UBUNTU-CVE-2013-6426
Summary:
Details: The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 does not properly enforce policy rules, which allows local in-instance users to bypass intended access restrictions and (1) create a stack via the CreateStack method or (2) update a stack via the UpdateStack method.
References: https://ubuntu.com/security/CVE-2013-6426, http://www.openwall.com/lists/oss-security/2013/12/11/10, http://lists.openstack.org/pipermail/openstack-announce/2013-December/000170.html, https://www.cve.org/CVERecord?id=CVE-2013-6426
Affected packages
Package
Name: heat
Purl: pkg:deb/ubuntu/[email protected]~rc1-0ubuntu1?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
