Exposure of Sensitive Information to an Unauthorized Actor in OpenStack tripleo-heat-templates
Moderate severity
GitHub Reviewed
Published
Mar 24, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Mar 23, 2022
Published to the GitHub Advisory Database
Mar 24, 2022
Reviewed
Mar 31, 2022
Last updated
Jan 27, 2023
An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or hostname. An attacker could exploit this by checking the
www_authenticate_uri parameter
(which is visible to all end users) in configuration files. This would give sensitive information which may aid in additional system exploitation. A patch is available on themaster
branch and anticipated to be part of version 11.6.1.References