CVE-2014-4615
OpenStack PyCADF <0.5.0, Telemetry <2013.2.4, Neutron <2014.1.2, Ju...
Title source: llmDescription
The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).
References (9)
Scores
EPSS
0.0075
EPSS Percentile
72.9%
Classification
CWE
CWE-200
Status
draft
Affected Products (26)
redhat/openstack
canonical/ubuntu_linux
openstack/neutron
openstack/neutron
openstack/neutron
openstack/oslo
openstack/pycadf
< 0.5.0
openstack/pycadf
openstack/pycadf
openstack/pycadf
openstack/pycadf
openstack/pycadf
openstack/pycadf
openstack/pycadf
openstack/pycadf
... and 11 more
Timeline
Published
Aug 19, 2014
Tracked Since
Feb 18, 2026