← Back

CVE-2014-4615

nvd nist
Published: Aug 19, 2014Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:P/I:N/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).

Affected (26)

1 product
Ubuntu Linux
1 product
Openstack
4 products
Neutron
Oslo
Pycadf
Telemetry (ceilometer)
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 14.04
Version 4.0
Configuration B
24 vulnerable
Vulnerable SoftwareAffected Versions
Openstack
Version 2014.1.1
Version 2014.1
Version juno1
All versions
Openstack
Up to 0.5.0
Version 0.1.1
Version 0.1.2
Version 0.1.3
Version 0.1.4
Version 0.1.5
Version 0.1.6
Version 0.1.7
Version 0.1.8
Version 0.1.9
Version 0.1
Version 0.2.1
Version 0.2.2
Version 0.2
Version 0.3.1
Version 0.3
Version 0.4.1
Version 0.4
Openstack
Version 2013.2
Version 2014.1

References (18)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.