CVE-2014-4615

EUVD-2014-4542
The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 72%
Affected Products (NVD)
VendorProductVersion
redhatopenstack
4.0
canonicalubuntu_linux
14.04
openstackneutron
2014.1
openstackneutron
2014.1.1
openstackoslo
-
openstackpycadf
𝑥
≤ 0.5.0
openstackpycadf
0.1
openstackpycadf
0.1.1
openstackpycadf
0.1.2
openstackpycadf
0.1.3
openstackpycadf
0.1.4
openstackpycadf
0.1.5
openstackpycadf
0.1.6
openstackpycadf
0.1.7
openstackpycadf
0.1.8
openstackpycadf
0.1.9
openstackpycadf
0.2
openstackpycadf
0.2.1
openstackpycadf
0.2.2
openstackpycadf
0.3
openstackpycadf
0.3.1
openstackpycadf
0.4
openstackpycadf
0.4.1
openstacktelemetry_\(ceilometer\)
2013.2
openstacktelemetry_\(ceilometer\)
2014.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ceilometer
bookworm
1:19.0.0-3
fixed
bullseye
1:15.0.0-3
fixed
sid
1:23.0.0-1
fixed
trixie
1:23.0.0-1
fixed
neutron
bookworm
2:21.0.0-7
fixed
bullseye
2:17.2.1-0+deb11u1
fixed
bullseye (security)
2:17.2.1-0+deb11u1
fixed
sid
2:25.0.0-1
fixed
trixie
2:25.0.0-1
fixed
python-pycadf
bookworm
3.1.1-2
fixed
bullseye
3.1.1-2
fixed
sid
3.1.1-3
fixed
trixie
3.1.1-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ceilometer
lucid
dne
precise
dne
saucy
ignored
trusty
Fixed 2014.1.2-0ubuntu1
released
neutron
lucid
dne
precise
dne
saucy
not-affected
trusty
Fixed 1:2014.1.2-0ubuntu1
released
python-pycadf
lucid
dne
precise
dne
saucy
dne
trusty
Fixed 0.4.1-0ubuntu1.1
released