CVE-2015-5295: Fedoraproject Fedora
Medium severity, CVSS 5.4. EPSS: 2.9% chance of exploitation in the next 30 days.
The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template, as demonstrated by file:///dev/zero.
Affected products
- Fedoraproject Fedora: version 23 only
- Openstack Orchestration API: from 5.0.0, before 5.0.1 (fixed in 5.0.1); from 2015.1.0, before 2015.1.3 (fixed in 2015.1.3)
- Oracle Solaris: version 11.3 only
- Red Hat Openstack: version 7.0 only
Published 2016-01-20. Last modified 2026-06-17.