CVE-2014-4615

The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
VendorProductVersion
redhatopenstack
4.0
canonicalubuntu_linux
14.04
openstackneutron
2014.1
openstackneutron
2014.1.1
openstackoslo
-
openstackpycadf
𝑥
≤ 0.5.0
openstackpycadf
0.1
openstackpycadf
0.1.1
openstackpycadf
0.1.2
openstackpycadf
0.1.3
openstackpycadf
0.1.4
openstackpycadf
0.1.5
openstackpycadf
0.1.6
openstackpycadf
0.1.7
openstackpycadf
0.1.8
openstackpycadf
0.1.9
openstackpycadf
0.2
openstackpycadf
0.2.1
openstackpycadf
0.2.2
openstackpycadf
0.3
openstackpycadf
0.3.1
openstackpycadf
0.4
openstackpycadf
0.4.1
openstacktelemetry_\(ceilometer\)
2013.2
openstacktelemetry_\(ceilometer\)
2014.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ceilometer
bullseye
1:15.0.0-3
fixed
bookworm
1:19.0.0-3
fixed
sid
1:23.0.0-1
fixed
trixie
1:23.0.0-1
fixed
neutron
bullseye (security)
2:17.2.1-0+deb11u1
fixed
bullseye
2:17.2.1-0+deb11u1
fixed
bookworm
2:21.0.0-7
fixed
sid
2:25.0.0-1
fixed
trixie
2:25.0.0-1
fixed
python-pycadf
bookworm
3.1.1-2
fixed
bullseye
3.1.1-2
fixed
sid
3.1.1-3
fixed
trixie
3.1.1-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ceilometer
trusty
Fixed 2014.1.2-0ubuntu1
released
saucy
ignored
precise
dne
lucid
dne
neutron
trusty
Fixed 1:2014.1.2-0ubuntu1
released
saucy
not-affected
precise
dne
lucid
dne
python-pycadf
trusty
Fixed 0.4.1-0ubuntu1.1
released
saucy
dne
precise
dne
lucid
dne