An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A malicious system user could exploit this flaw to access sensitive information.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "2014.1.5-0ubuntu1", "binary_name": "heat-api" }, { "binary_version": "2014.1.5-0ubuntu1", "binary_name": "heat-api-cfn" }, { "binary_version": "2014.1.5-0ubuntu1", "binary_name": "heat-api-cloudwatch" }, { "binary_version": "2014.1.5-0ubuntu1", "binary_name": "heat-common" }, { "binary_version": "2014.1.5-0ubuntu1", "binary_name": "heat-engine" }, { "binary_version": "2014.1.5-0ubuntu1", "binary_name": "python-heat" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1:6.1.2-0ubuntu1", "binary_name": "heat-api" }, { "binary_version": "1:6.1.2-0ubuntu1", "binary_name": "heat-api-cfn" }, { "binary_version": "1:6.1.2-0ubuntu1", "binary_name": "heat-api-cloudwatch" }, { "binary_version": "1:6.1.2-0ubuntu1", "binary_name": "heat-common" }, { "binary_version": "1:6.1.2-0ubuntu1", "binary_name": "heat-engine" }, { "binary_version": "1:6.1.2-0ubuntu1", "binary_name": "python-heat" } ] }