First published: Tue Aug 19 2014(Updated: )
The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Openstack | =4.0 | |
Canonical Ubuntu Linux | =14.04 | |
OpenStack Neutron | =2014.1 | |
OpenStack Neutron | =2014.1.1 | |
OpenStack Neutron | =juno1 | |
OpenStack Oslo | ||
OpenStack PyCADF | <=0.5.0 | |
OpenStack PyCADF | =0.1 | |
OpenStack PyCADF | =0.1.1 | |
OpenStack PyCADF | =0.1.2 | |
OpenStack PyCADF | =0.1.3 | |
OpenStack PyCADF | =0.1.4 | |
OpenStack PyCADF | =0.1.5 | |
OpenStack PyCADF | =0.1.6 | |
OpenStack PyCADF | =0.1.7 | |
OpenStack PyCADF | =0.1.8 | |
OpenStack PyCADF | =0.1.9 | |
OpenStack PyCADF | =0.2 | |
OpenStack PyCADF | =0.2.1 | |
OpenStack PyCADF | =0.2.2 | |
OpenStack PyCADF | =0.3 | |
OpenStack PyCADF | =0.3.1 | |
OpenStack PyCADF | =0.4 | |
OpenStack PyCADF | =0.4.1 | |
Openstack Telemetry \(ceilometer\) | =2013.2 | |
Openstack Telemetry \(ceilometer\) | =2014.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.