HIGH7.4
PYSEC-2026-1751
OpenStack Heat information leak vulnerability
Quick fix
PYSEC-2026-1751 — openstack-heat: upgrade to the fixed version with the command below.
pip install --upgrade 'openstack-heat>=20.0.0'Details
An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are supposed to remain hidden. This has a low impact to the confidentiality, integrity, and availability of the system.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/openstack-heat
Introduced in:
0Fixed in: 20.0.0Fix
pip install --upgrade 'openstack-heat>=20.0.0'References
- https://nvd.nist.gov/vuln/detail/CVE-2023-1625[ADVISORY]
- https://github.com/openstack/heat/commit/a49526c278e52823080c7f3fcb72785b93fd4dcb[WEB]
- https://access.redhat.com/security/cve/CVE-2023-1625[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2181621[WEB]
- https://github.com/openstack/heat[PACKAGE]
- https://launchpad.net/bugs/1999665[WEB]
- https://pypi.org/project/openstack-heat[PACKAGE]
- https://github.com/advisories/GHSA-5836-grcc-8j89[ADVISORY]