OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list.
{ "binaries": [ { "binary_name": "heat-api", "binary_version": "2014.1-0ubuntu1.1" }, { "binary_name": "heat-api-cfn", "binary_version": "2014.1-0ubuntu1.1" }, { "binary_name": "heat-api-cloudwatch", "binary_version": "2014.1-0ubuntu1.1" }, { "binary_name": "heat-common", "binary_version": "2014.1-0ubuntu1.1" }, { "binary_name": "heat-engine", "binary_version": "2014.1-0ubuntu1.1" }, { "binary_name": "python-heat", "binary_version": "2014.1-0ubuntu1.1" } ], "availability": "No subscription required" }