Bugzilla – Bug 855331
VUL-0: CVE-2013-6428: openstack-heat: ReST API doesn't respect tenant scoping
Last modified: 2014-09-25 15:53:49 UTC
Public via oss-security: OpenStack Security Advisory: 2013-035 CVE: CVE-2013-6428 Date: December 11, 2013 Title: Heat ReST API doesn't respect tenant scoping Reporter: Steven Hardy (Red Hat) Products: Heat Affects: All supported releases Description: Steven Hardy from Red Hat reported a vulnerability in the Heat ReST API. By changing the request path, an authenticated client may override their tenant scope resulting in privilege escalation. Only setups exposing the Heat orchestration ReST interface are affected. Icehouse (development branch) fix: https://review.openstack.org/61455 Havana fix: https://review.openstack.org/61456 Notes: This fix will be included in the icehouse-2 development milestone and in a future 2013.2.1 release. References: http://comments.gmane.org/gmane.comp.security.oss.general/11678 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-6428 https://bugzilla.redhat.com/show_bug.cgi?id=1039144 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6428 https://launchpad.net/bugs/1256983
bugbot adjusting priority
Grizzly patch for 2.0: https://bugs.launchpad.net/heat/+bug/1256983/+attachment/3921986/+files/Grizzly_0001-Deny-API-requests-where-context-doesn-t-match-path.patch (we should already have the Havana fix in our Cloud 3 packages)
The SWAMPID for this issue is 56958. This issue was rated as moderate. Please submit fixed packages until 2014-04-22. When done, please reassign the bug to security-team@suse.de. Patchinfo will be handled by security team.
SUSE-RU-2014:1215-1: An update that has three recommended fixes can now be installed. Category: recommended (low) Bug References: 855331,855333,882866 CVE References: Sources used: SUSE Cloud 3 (src): openstack-ceilometer-2013.2.4.dev5.ga2c909c-0.9.2, openstack-ceilometer-doc-2013.2.4.dev5.ga2c909c-0.9.2, openstack-cinder-2013.2.4.dev2.g81259f3-0.9.2, openstack-cinder-doc-2013.2.4.dev2.g81259f3-0.9.7, openstack-glance-2013.2.4.dev3.g396ca82-0.9.2, openstack-glance-doc-2013.2.4.dev3.g396ca82-0.9.7, openstack-heat-2013.2.4.dev3.g6f91215-0.11.1, openstack-heat-cfntools-1.2.7.5.g9bd9604-0.9.2, openstack-nova-2013.2.4.dev18.g0bf0bb4-0.9.2, openstack-nova-doc-2013.2.4.dev18.g0bf0bb4-0.9.7
released