OSSN-0012: OpenSSL Heartbleed vulnerability can lead to OpenStack compromise

Summary

A vulnerability in OpenSSL can lead to leaking of confidential data protected by SSL/TLS in an OpenStack deployment.

Affected Services / Software

Grizzly, Havana, OpenSSL

Discussion

A vulnerability in OpenSSL code-named Heartbleed was recently discovered that allows remote attackers limited access to data in the memory of any service using OpenSSL to provide encryption for network communications. This can include key material used for SSL/TLS, which means that any confidential data that has been sent over SSL/TLS may be compromised. For full details, see: http://heartbleed.com/

While OpenStack software itself is not directly affected, any deployment of OpenStack is very likely using OpenSSL to provide SSL/TLS functionality.

Contacts / References

Author: Nathan Kinder (Red Hat), Robert Clark (HP)