An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_name": "heat-api", "binary_version": "2014.1.5-0ubuntu1" }, { "binary_name": "heat-api-cfn", "binary_version": "2014.1.5-0ubuntu1" }, { "binary_name": "heat-api-cloudwatch", "binary_version": "2014.1.5-0ubuntu1" }, { "binary_name": "heat-common", "binary_version": "2014.1.5-0ubuntu1" }, { "binary_name": "heat-engine", "binary_version": "2014.1.5-0ubuntu1" }, { "binary_name": "python-heat", "binary_version": "2014.1.5-0ubuntu1" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_name": "heat-api", "binary_version": "1:6.1.2-0ubuntu1" }, { "binary_name": "heat-api-cfn", "binary_version": "1:6.1.2-0ubuntu1" }, { "binary_name": "heat-api-cloudwatch", "binary_version": "1:6.1.2-0ubuntu1" }, { "binary_name": "heat-common", "binary_version": "1:6.1.2-0ubuntu1" }, { "binary_name": "heat-engine", "binary_version": "1:6.1.2-0ubuntu1" }, { "binary_name": "python-heat", "binary_version": "1:6.1.2-0ubuntu1" } ] }