Vulnerability Description
In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0, and ==7.0.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Openstack | Heat | 5.0.3 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/94205Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:1450
- https://access.redhat.com/errata/RHSA-2017:1456
- https://access.redhat.com/errata/RHSA-2017:1464
- https://bugs.launchpad.net/ossa/+bug/1606500Issue TrackingThird Party Advisory
- http://www.securityfocus.com/bid/94205Third Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2017:1450
- https://access.redhat.com/errata/RHSA-2017:1456
- https://access.redhat.com/errata/RHSA-2017:1464
- https://bugs.launchpad.net/ossa/+bug/1606500Issue TrackingThird Party Advisory
FAQ
What is CVE-2016-9185?
CVE-2016-9185 is a vulnerability with a CVSS score of 4.3 (MEDIUM). In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 <...
How severe is CVE-2016-9185?
CVE-2016-9185 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-9185?
Check the references section above for vendor advisories and patch information. Affected products include: Openstack Heat.