Launching a new Heat stack and giving the template from an URL like http://localhost:22 Results in an error message like: ERROR: Could not retrieve template: Failed to retrieve template: ('Connection aborted.', BadStatusLine('SSH-2.0-OpenSSH_6.6.1\r\n',)) This is a security issue as it allows users to scan the network for listening ports. Reproducible: Always
cleaned up
CVE-2016-9185 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-9185): In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions are <=5.0.3, >=6.0.0 <=6.1.0, and ==7.0.0.
GLSA Vote: No