{"id":"CVE-2013-6428","details":"The ReST API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 allows remote authenticated users to bypass the tenant scoping restrictions via a modified tenant_id in the request path.","modified":"2026-04-10T03:43:07.396594Z","published":"2013-12-14T17:21:47Z","references":[{"type":"ADVISORY","url":"http://rhn.redhat.com/errata/RHSA-2014-0090.html"},{"type":"EVIDENCE","url":"https://launchpad.net/bugs/1256983"},{"type":"FIX","url":"https://launchpad.net/bugs/1256983"},{"type":"WEB","url":"http://seclists.org/oss-sec/2013/q4/479"}],"schema_version":"1.7.5"}