CVE-2014-4615

The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, … (CVE-2014-4615)

Description

The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).

Source: CVELISTV5NVD

Metrics

Severity
none
no public PoC known
85.5 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
2.8 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2014-08-19 18:00 UTC

Affected operating systems

  • linux

    canonical / ubuntu_linux14.04

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • openstack

    neutron

  • openstack

    oslo

  • openstack

    pycadf0.5.0

  • openstack

    pycadf

  • openstack

    telemetry_\(ceilometer\)

  • redhat

    openstack

References & sources

IDCVE-2014-4615