An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "2014.1.5-0ubuntu1",
"binary_name": "heat-api"
},
{
"binary_version": "2014.1.5-0ubuntu1",
"binary_name": "heat-api-cfn"
},
{
"binary_version": "2014.1.5-0ubuntu1",
"binary_name": "heat-api-cloudwatch"
},
{
"binary_version": "2014.1.5-0ubuntu1",
"binary_name": "heat-common"
},
{
"binary_version": "2014.1.5-0ubuntu1",
"binary_name": "heat-engine"
},
{
"binary_version": "2014.1.5-0ubuntu1",
"binary_name": "python-heat"
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "1:6.1.2-0ubuntu1",
"binary_name": "heat-api"
},
{
"binary_version": "1:6.1.2-0ubuntu1",
"binary_name": "heat-api-cfn"
},
{
"binary_version": "1:6.1.2-0ubuntu1",
"binary_name": "heat-api-cloudwatch"
},
{
"binary_version": "1:6.1.2-0ubuntu1",
"binary_name": "heat-common"
},
{
"binary_version": "1:6.1.2-0ubuntu1",
"binary_name": "heat-engine"
},
{
"binary_version": "1:6.1.2-0ubuntu1",
"binary_name": "python-heat"
}
]
}