[openstack-announce] [OSSA 2013-034] Heat CFN policy rules not all enforced (CVE-2013-6426)

2013-12-11 Thread Jeremy Stanley
OpenStack Security Advisory: 2013-034 CVE: CVE-2013-6426 Date: December 11, 2013 Title: Heat CFN policy rules not all enforced Reporter: Steven Hardy (Red Hat) Products: Heat Affects: All supported releases Description: Steven Hardy from Red Hat reported a vulnerability in Heat's default API polic

[openstack-announce] [OSSA 2013-034] Heat CFN policy rules not all enforced (CVE-2013-6426)

2013-12-11 Thread Jeremy Stanley
OpenStack Security Advisory: 2013-034 CVE: CVE-2013-6426 Date: December 11, 2013 Title: Heat CFN policy rules not all enforced Reporter: Steven Hardy (Red Hat) Products: Heat Affects: All supported releases Description: Steven Hardy from Red Hat reported a vulnerability in Heat's default API polic