Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-4615

Опубликовано: 20 мая 2014
Источник: redhat
CVSS2: 5

Описание

The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).

It was found that authentication tokens were not properly sanitized from the message queue by the notifier middleware. An attacker with read access to the message queue could possibly use this flaw to intercept an authentication token and gain elevated privileges. Note that all services using the notifier middleware configured after the auth_token middleware pipeline were affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)openstack-ceilometerAffected
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)openstack-neutronAffected
Red Hat Enterprise Linux OpenStack Platform 5 (Icehouse)python-pycadfAffected
Red Hat OpenStack Platform 3openstack-ceilometerNot affected
Red Hat OpenStack Platform 3openstack-quantumNot affected
Red Hat OpenStack Platform 4openstack-neutronNot affected
OpenStack 4 for RHEL 6openstack-ceilometerFixedRHSA-2014:105013.08.2014

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=1112945pycadf: token leak to message queue

5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 11 лет назад

The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).

nvd
больше 11 лет назад

The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).

debian
больше 11 лет назад

The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemet ...

github
больше 3 лет назад

The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).

5 Medium

CVSS2