In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0, and ==7.0.0.
{ "availability": "No subscription required", "ubuntu_priority": "low", "binaries": [ { "binary_name": "heat-api", "binary_version": "1:6.1.2-0ubuntu1" }, { "binary_name": "heat-api-cfn", "binary_version": "1:6.1.2-0ubuntu1" }, { "binary_name": "heat-api-cloudwatch", "binary_version": "1:6.1.2-0ubuntu1" }, { "binary_name": "heat-common", "binary_version": "1:6.1.2-0ubuntu1" }, { "binary_name": "heat-engine", "binary_version": "1:6.1.2-0ubuntu1" }, { "binary_name": "python-heat", "binary_version": "1:6.1.2-0ubuntu1" } ] }