Vulnerability Description
The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Openstack | 4.0 |
| Canonical | Ubuntu Linux | 14.04 |
| Openstack | Neutron | 2014.1 |
| Openstack | Oslo | - |
| Openstack | Pycadf | <= 0.5.0 |
| Openstack | Telemetry \(Ceilometer\) | 2013.2 |
Related Weaknesses (CWE)
References
- http://rhn.redhat.com/errata/RHSA-2014-1050.html
- http://secunia.com/advisories/60643
- http://secunia.com/advisories/60736
- http://secunia.com/advisories/60766
- http://www.openwall.com/lists/oss-security/2014/06/23/8
- http://www.openwall.com/lists/oss-security/2014/06/24/6
- http://www.openwall.com/lists/oss-security/2014/06/25/6
- http://www.securityfocus.com/bid/68149
- http://www.ubuntu.com/usn/USN-2311-1
- http://rhn.redhat.com/errata/RHSA-2014-1050.html
- http://secunia.com/advisories/60643
- http://secunia.com/advisories/60736
- http://secunia.com/advisories/60766
- http://www.openwall.com/lists/oss-security/2014/06/23/8
- http://www.openwall.com/lists/oss-security/2014/06/24/6
FAQ
What is CVE-2014-4615?
CVE-2014-4615 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo...
How severe is CVE-2014-4615?
CVE-2014-4615 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-4615?
Check the references section above for vendor advisories and patch information. Affected products include: Redhat Openstack, Canonical Ubuntu Linux, Openstack Neutron, Openstack Oslo, Openstack Pycadf.