Source: heat Version: 1:7.0.0-1 Severity: grave Tags: security upstream patch Forwarded: https://bugs.launchpad.net/ossa/+bug/1606500
Hi, the following vulnerability was published for heat. CVE-2016-9185[0]: | In OpenStack Heat, by launching a new Heat stack with a local URL an | authenticated user may conduct network discovery revealing internal | network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0, | and ==7.0.0. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2016-9185 [1] https://bugs.launchpad.net/ossa/+bug/1606500 Please adjust the affected versions in the BTS as needed. Regards, Salvatore