Safety vulnerability ID: 26164
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Tripleo-heat-templates 0.8.7 includes a fix for CVE-2015-5271: A flaw was discovered in the pipeline ordering of OpenStack Object Storage's staticweb middleware in the swiftproxy configuration generated from the openstack-tripleo-heat-templates package (OpenStack director). The staticweb middleware was incorrectly configured before the Identity Service, and under some conditions an attacker could use this flaw to gain unauthenticated access to private data.
https://opendev.org/openstack/tripleo-heat-templates/commit/1730d95acdbee7c7bbcfe1eba8a48ef2b0cc1476
Latest version: 18.0.0
Heat templates for deploying OpenStack with OpenStack.
The TripleO Heat templates (tripleo-heat-templates) do not properly order the Identity Service (keystone) before the OpenStack Object Storage (Swift) staticweb middleware in the swiftproxy pipeline when the staticweb middleware is enabled, which might allow remote attackers to obtain sensitive information from private containers via unspecified vectors.
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application