—
PYSEC-2026-889
OpenStack Heat template URL information leakage
Quick fix
PYSEC-2026-889 — openstack-heat: upgrade to the fixed version with the command below.
pip install --upgrade 'openstack-heat>=5.0.0a0'Details
OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/openstack-heat
Introduced in:
0Fixed in: 5.0.0a0Fix
pip install --upgrade 'openstack-heat>=5.0.0a0'References
- https://nvd.nist.gov/vuln/detail/CVE-2014-3801[ADVISORY]
- https://bugs.launchpad.net/heat/+bug/1311223[WEB]
- https://git.openstack.org/cgit/openstack/heat[PACKAGE]
- https://git.openstack.org/cgit/openstack/heat/commit/?id=03dd894de4ad905dc170e358fad27d9c8ed62a73[WEB]
- https://git.openstack.org/cgit/openstack/heat/commit/?id=7e114a38712da8947ee7ad93eabda34f5e4aa65a[WEB]
- https://git.openstack.org/cgit/openstack/heat/commit/?id=a02ff20509171346d2a1d2a9df7c81aada134c52[WEB]
- https://web.archive.org/web/20200229061233/https://www.securityfocus.com/bid/67505[WEB]
- http://rhn.redhat.com/errata/RHSA-2014-1687.html[WEB]
- http://www.openwall.com/lists/oss-security/2014/05/20/1[WEB]
- http://www.openwall.com/lists/oss-security/2014/05/20/6[WEB]
- http://www.ubuntu.com/usn/USN-2249-1[WEB]
- https://pypi.org/project/openstack-heat[PACKAGE]
- https://github.com/advisories/GHSA-86qj-4h55-fvpw[ADVISORY]