[OSSA 2014-016] User's provider templates show up in listing of resource types globally across tenants (CVE-2014-3801)
Bug #1311223 reported by
Jason Dunsmore
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
OpenStack Heat |
Fix Released
|
Critical
|
Jason Dunsmore | ||
Havana |
Fix Released
|
Critical
|
Bernhard M. Wiedemann | ||
Icehouse |
Fix Released
|
Critical
|
Bernhard M. Wiedemann | ||
OpenStack Security Advisory |
Fix Released
|
Medium
|
Tristan Cacqueray |
Bug Description
During stack creation of a template that uses a provider template, the URL of the provider template will be temporarily listed in the output of "heat resource-type-list" for all tenants. The URL disappears from the listing after a certain point in the stack creation. The provider template resource type should be restricted to the tenant creating the stack.
CVE References
information type: | Private Security → Public Security |
Changed in ossa: | |
status: | New → Incomplete |
Changed in ossa: | |
importance: | Undecided → Medium |
summary: |
User's provider templates show up in listing of resource types globally - across tenants + across tenants (CVE-2014-3801) |
Changed in ossa: | |
status: | Confirmed → In Progress |
summary: |
- User's provider templates show up in listing of resource types globally - across tenants (CVE-2014-3801) + [OSSA 2014-016] User's provider templates show up in listing of resource + types globally across tenants (CVE-2014-3801) |
Changed in ossa: | |
assignee: | nobody → Tristan Cacqueray (tristan-cacqueray) |
Changed in ossa: | |
status: | In Progress → Fix Committed |
status: | Fix Committed → Fix Released |
tags: | removed: in-stable-havana in-stable-icehouse |
Changed in heat: | |
assignee: | nobody → Jason Dunsmore (jasondunsmore) |
Changed in heat: | |
milestone: | none → juno-1 |
status: | Fix Committed → Fix Released |
Changed in heat: | |
milestone: | juno-1 → 2014.2 |
To post a comment you must log in.
Reproduce with:
heat stack-create -f http:// dunsmor. com/pastebin/ 1398191902. txt test
heat resource-type-list
Using the latest Heat master branch.