Upstream information

CVE-2014-0041 at MITRE

Description

OpenStack Heat Templates (heat-templates), as used in Red Hat Enterprise Linux OpenStack Platform 4.0, sets sslverify to false for certain Yum repositories, which disables SSL protection and allows man-in-the-middle attackers to prevent updates via unspecified vectors.

SUSE information

Overall state of this security issue: Resolved

This issue is currently not rated by SUSE as it is not affecting the SUSE Enterprise products.

CVSS v2 Scores
CVSS detail National Vulnerability Database
Base Score 4.3
Vector AV:N/AC:M/Au:N/C:N/I:P/A:N
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact Partial
Availability Impact None
SUSE Bugzilla entries: 861481 [RESOLVED / WONTFIX], 861482 [RESOLVED / DUPLICATE]

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
SUSE OpenStack Cloud 6
  • openstack-heat-templates >= 0.0.0+git.1452795102.e53f5d3-1.1
Patchnames:
SUSE OpenStack Cloud 6 GA openstack-heat-templates-0.0.0+git.1451027929.810f40b-1.1


SUSE Timeline for this CVE

CVE page created: Thu Jan 30 05:35:32 2014
CVE page last modified: Sat May 9 11:27:44 2026