VYPR
Unrated severityNVD Advisory· Published Dec 14, 2013· Updated Apr 29, 2026

CVE-2013-6426

CVE-2013-6426

Description

The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 does not properly enforce policy rules, which allows local in-instance users to bypass intended access restrictions and (1) create a stack via the CreateStack method or (2) update a stack via the UpdateStack method.

Affected products

1
  • cpe:2.3:a:openstack:heat:*:*:*:*:*:*:*:*
    Range: <=2013.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.