5

CVE-2014-4615

The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).

Data is provided by the National Vulnerability Database (NVD)
RedhatOpenstack Version4.0
CanonicalUbuntu Linux Version14.04 SwEditionlts
OpenstackNeutron Version2014.1
OpenstackNeutron Version2014.1.1
OpenstackNeutron Versionjuno1
OpenstackOslo Version-
OpenstackPycadf Version <= 0.5.0
OpenstackPycadf Version0.1
OpenstackPycadf Version0.1.1
OpenstackPycadf Version0.1.2
OpenstackPycadf Version0.1.3
OpenstackPycadf Version0.1.4
OpenstackPycadf Version0.1.5
OpenstackPycadf Version0.1.6
OpenstackPycadf Version0.1.7
OpenstackPycadf Version0.1.8
OpenstackPycadf Version0.1.9
OpenstackPycadf Version0.2
OpenstackPycadf Version0.2.1
OpenstackPycadf Version0.2.2
OpenstackPycadf Version0.3
OpenstackPycadf Version0.3.1
OpenstackPycadf Version0.4
OpenstackPycadf Version0.4.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.75% 0.708
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.