CVE-2014-4615

OpenStack PyCADF <0.5.0, Telemetry <2013.2.4, Neutron <2014.1.2, Ju...

Title source: llm
STIX 2.1

Description

The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/68149
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/06/25/6
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60766
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/06/23/8
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/06/24/6
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2311-1
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60736
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1050.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/60643

Scores

EPSS 0.0075
EPSS Percentile 73.4%

Details

CWE
CWE-200
Status published
Products (26)
canonical/ubuntu_linux 14.04
openstack/neutron 2014.1
openstack/neutron 2014.1.1
openstack/neutron juno1
openstack/oslo
openstack/pycadf 0.1
openstack/pycadf 0.1.1
openstack/pycadf 0.1.2
openstack/pycadf 0.1.3
openstack/pycadf 0.1.4
... and 16 more
Published Aug 19, 2014
Tracked Since Feb 18, 2026