Bug 855331 (CVE-2013-6428) - VUL-0: CVE-2013-6428: openstack-heat: ReST API doesn't respect tenant scoping
Summary: VUL-0: CVE-2013-6428: openstack-heat: ReST API doesn't respect tenant scoping
Status: RESOLVED FIXED
Alias: CVE-2013-6428
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Deadline: 2014-04-22
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: maint:running:56958:moderate
Keywords:
Depends on:
Blocks:
 
Reported: 2013-12-13 10:26 UTC by Alexander Bergmann
Modified: 2014-09-25 15:53 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2013-12-13 10:26:09 UTC
Public via oss-security:

OpenStack Security Advisory: 2013-035
CVE: CVE-2013-6428
Date: December 11, 2013
Title: Heat ReST API doesn't respect tenant scoping
Reporter: Steven Hardy (Red Hat)
Products: Heat
Affects: All supported releases

Description:
Steven Hardy from Red Hat reported a vulnerability in the Heat ReST
API. By changing the request path, an authenticated client may
override their tenant scope resulting in privilege escalation. Only
setups exposing the Heat orchestration ReST interface are affected.

Icehouse (development branch) fix:
https://review.openstack.org/61455

Havana fix:
https://review.openstack.org/61456

Notes:
This fix will be included in the icehouse-2 development milestone
and in a future 2013.2.1 release.


References:
http://comments.gmane.org/gmane.comp.security.oss.general/11678
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-6428
https://bugzilla.redhat.com/show_bug.cgi?id=1039144
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6428
https://launchpad.net/bugs/1256983
Comment 1 Swamp Workflow Management 2013-12-13 23:00:20 UTC
bugbot adjusting priority
Comment 2 Vincent Untz 2014-01-08 14:04:58 UTC
Grizzly patch for 2.0: https://bugs.launchpad.net/heat/+bug/1256983/+attachment/3921986/+files/Grizzly_0001-Deny-API-requests-where-context-doesn-t-match-path.patch

(we should already have the Havana fix in our Cloud 3 packages)
Comment 4 Swamp Workflow Management 2014-04-08 15:24:26 UTC
The SWAMPID for this issue is 56958.
This issue was rated as moderate.
Please submit fixed packages until 2014-04-22.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 6 Swamp Workflow Management 2014-09-25 00:07:23 UTC
SUSE-RU-2014:1215-1: An update that has three recommended fixes can now be installed.

Category: recommended (low)
Bug References: 855331,855333,882866
CVE References: 
Sources used:
SUSE Cloud 3 (src):    openstack-ceilometer-2013.2.4.dev5.ga2c909c-0.9.2, openstack-ceilometer-doc-2013.2.4.dev5.ga2c909c-0.9.2, openstack-cinder-2013.2.4.dev2.g81259f3-0.9.2, openstack-cinder-doc-2013.2.4.dev2.g81259f3-0.9.7, openstack-glance-2013.2.4.dev3.g396ca82-0.9.2, openstack-glance-doc-2013.2.4.dev3.g396ca82-0.9.7, openstack-heat-2013.2.4.dev3.g6f91215-0.11.1, openstack-heat-cfntools-1.2.7.5.g9bd9604-0.9.2, openstack-nova-2013.2.4.dev18.g0bf0bb4-0.9.2, openstack-nova-doc-2013.2.4.dev18.g0bf0bb4-0.9.7
Comment 7 Marcus Meissner 2014-09-25 15:53:49 UTC
released