CVE-2014-4615

OpenStack PyCADF <0.5.0, Telemetry <2013.2.4, Neutron <2014.1.2, Ju...

Title source: llm

Description

The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).

Scores

EPSS 0.0075
EPSS Percentile 72.9%

Classification

CWE
CWE-200
Status draft

Affected Products (26)

redhat/openstack
canonical/ubuntu_linux
openstack/neutron
openstack/neutron
openstack/neutron
openstack/oslo
openstack/pycadf < 0.5.0
openstack/pycadf
openstack/pycadf
openstack/pycadf
openstack/pycadf
openstack/pycadf
openstack/pycadf
openstack/pycadf
openstack/pycadf
... and 11 more

Timeline

Published Aug 19, 2014
Tracked Since Feb 18, 2026