UBUNTU-CVE-2014-4615
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-4615
UBUNTU-CVE-2014-4615
Summary:
Details: The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).
References: https://ubuntu.com/security/CVE-2014-4615, http://www.openwall.com/lists/oss-security/2014/06/23/8, http://lists.openstack.org/pipermail/openstack-announce/2014-June/000245.html, https://ubuntu.com/security/notices/USN-2311-1, https://ubuntu.com/security/notices/USN-2311-2, https://ubuntu.com/security/notices/USN-2321-1, https://www.cve.org/CVERecord?id=CVE-2014-4615
Affected packages
Package
Name: ceilometer
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
