The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2014-08-19 11:55
Updated : 2017-01-06 19:00
NVD link : CVE-2014-4615
Mitre link : CVE-2014-4615
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
openstack
- neutron
- telemetry_\(ceilometer\)
- pycadf
- oslo
redhat
- openstack
canonical
- ubuntu_linux