Vulnerabilities (CVE)

Filtered by vendor Openstack Subscribe
Filtered by product Heat
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-2621 2 Openstack, Redhat 2 Heat, Openstack 2022-05-01 2.1 LOW 5.5 MEDIUM
An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.
CVE-2016-9185 1 Openstack 1 Heat 2018-01-05 4.0 MEDIUM 4.3 MEDIUM
In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0, and ==7.0.0.