CVE-2014-3801: Openstack Heat

Low severity, CVSS 3.5. EPSS: 1.6% chance of exploitation in the next 30 days.

OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list.

Affected products

  • Openstack Heat: version 2013.2 only; version 2013.2.1 only; version 2013.2.2 only; version 2013.2.3 only; version 2014.1 only

Published 2014-05-23. Last modified 2026-06-17.