Description
The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2014-4542 | The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request). |
Ubuntu USN |
USN-2311-1 | pyCADF vulnerability |
Ubuntu USN |
USN-2311-2 | OpenStack Ceilometer vulnerability |
Ubuntu USN |
USN-2321-1 | OpenStack Neutron vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T11:20:27.019Z
Reserved: 2014-06-24T00:00:00.000Z
Link: CVE-2014-4615
No data.
Status : Modified
Published: 2014-08-19T18:55:02.873
Modified: 2026-05-06T22:30:45.220
Link: CVE-2014-4615
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN