An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or hostname. An attacker could exploit this by checking the www_authenticate_uri parameter (which is visible to all end users) in configuration files. This would give sensitive information which may aid in additional system exploitation. A patch is available on the master branch and anticipated to be part of version 11.6.1.
{
"github_reviewed_at": "2022-03-31T20:43:24Z",
"nvd_published_at": "2022-03-23T20:15:00Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-200",
"CWE-668"
],
"github_reviewed": true
}