In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0, and ==7.0.0.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_version": "1:6.1.2-0ubuntu1", "binary_name": "heat-api" }, { "binary_version": "1:6.1.2-0ubuntu1", "binary_name": "heat-api-cfn" }, { "binary_version": "1:6.1.2-0ubuntu1", "binary_name": "heat-api-cloudwatch" }, { "binary_version": "1:6.1.2-0ubuntu1", "binary_name": "heat-common" }, { "binary_version": "1:6.1.2-0ubuntu1", "binary_name": "heat-engine" }, { "binary_version": "1:6.1.2-0ubuntu1", "binary_name": "python-heat" } ] }