Heat
Vendor:
First CVE: Dec 14, 2013 · Active for 12 years
7
Total CVEs
More Total CVEs than 83% of tracked products
1.2
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
4.5
Avg CVSS
Higher Avg CVSS than 5% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Heat over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 14, 2013
12 years ago
Most Recent CVE
Aug 2, 2024
721 days ago
CVE Severity & Scoring
Heat7 CVEs
14%
86%
All CVEs352,231 CVEs
45%
40%
11%
LowMedium
Attack Vector
Local1 (14.3%)
Network3 (42.9%)
Unknown3 (42.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (57.1%)
High0 (0.0%)
Unknown3 (42.9%)
User Interaction
None4 (57.1%)
Unknown3 (42.9%)
Required0 (0.0%)
Privileges Required
Low4 (57.1%)
High0 (0.0%)
None0 (0.0%)
Unknown3 (42.9%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-2621MEDIUM An access-control flaw was found in the OpenStack Orchestration (heat) service before 8.0.0, 6.1.0 and 7.0.2 where a service log directory was improperly made world readable. A mal | Jul 27, 2018 | 5.5 | 20 | NO | NO |
CVE-2023-1625MEDIUM An information leak was discovered in OpenStack heat. This issue could allow a remote, authenticated attacker to use the 'stack show' command to reveal parameters which are suppose | Sep 24, 2023 | 5.0 | 19 | NO | NO |
CVE-2024-7319MEDIUM An incomplete fix for CVE-2023-1625 was found in openstack-heat. Sensitive information may possibly be disclosed through the OpenStack stack abandon command with the hidden feature | Aug 2, 2024 | 5.0 | 17 | NO | NO |
OpenStack Orchestration API (Heat) 2013.2 through 2013.2.3 and 2014.1, when creating the stack for a template using a provider template, allows remote authenticated users to obtain | May 23, 2014 | 3.5 | 17 | NO | NO |
CVE-2013-6428MEDIUM The ReST API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 allows remote authenticated users to bypass the tenant scoping restrictions | Dec 14, 2013 | 4.0 | 17 | NO | NO |
CVE-2016-9185MEDIUM In OpenStack Heat, by launching a new Heat stack with a local URL an authenticated user may conduct network discovery revealing internal network configuration. Affected versions ar | Nov 4, 2016 | 4.3 | 14 | NO | NO |
CVE-2013-6426MEDIUM The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 does not properly enforce policy rules, which allows l | Dec 14, 2013 | 4.0 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Heat
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.0.0 | 1 | 4.3 | 1.5% | 0 | 0 |
| 6.1.0 | 1 | 4.3 | 1.5% | 0 | 0 |
| 6.0.0 | 1 | 4.3 | 1.5% | 0 | 0 |
| 5.0.3 | 1 | 4.3 | 1.5% | 0 | 0 |
| 2014.1 | 1 | 3.5 | 1.6% | 0 | 0 |
| 2013.2.3 | 1 | 3.5 | 1.6% | 0 | 0 |
| 2013.2.2 | 1 | 3.5 | 1.6% | 0 | 0 |
| 2013.2.1 | 1 | 3.5 | 1.6% | 0 | 0 |
| 2013.2 | 1 | 3.5 | 1.6% | 0 | 0 |