CVE-2014-3801: Openstack Heat
Low severity, CVSS 3.5. EPSS: 1.6% chance of exploitation in the next 30 days.
OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain the provider template URL via the resource-type-list.
Affected products
- Openstack Heat: version 2013.2 only; version 2013.2.1 only; version 2013.2.2 only; version 2013.2.3 only; version 2014.1 only
Published 2014-05-23. Last modified 2026-06-17.