CVE-2014-4615
published 2014-08-19CVE-2014-4615: The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before…
PriorityP424medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.77%
84.7th percentile
The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | ceilometer | < ceilometer 2014.1.2-1 (bookworm) | ceilometer 2014.1.2-1 (bookworm) |
| debian | neutron | < ceilometer 2014.1.2-1 (bookworm) | ceilometer 2014.1.2-1 (bookworm) |
| debian | python-pycadf | < ceilometer 2014.1.2-1 (bookworm) | ceilometer 2014.1.2-1 (bookworm) |
| openstack | ceilometer | >= 0 < 2014.1.2-1 | 2014.1.2-1 |
| openstack | ceilometer | >= 0 < 2014.1.2-1 | 2014.1.2-1 |
| openstack | ceilometer | >= 0 < 2014.1.2-1 | 2014.1.2-1 |
| openstack | ceilometer | >= 0 < 2014.1.2-1 | 2014.1.2-1 |
| openstack | neutron | — | — |
| openstack | neutron | — | — |
| openstack | neutron | — | — |
| openstack | neutron | >= 0 < 2014.1.2-1 | 2014.1.2-1 |
| openstack | neutron | >= 0 < 2014.1.2-1 | 2014.1.2-1 |
| openstack | neutron | >= 0 < 2014.1.2-1 | 2014.1.2-1 |
| openstack | neutron | >= 0 < 2014.1.2-1 | 2014.1.2-1 |
| openstack | neutron | >= 0 < 1:2014.1.2-0ubuntu1.1 | 1:2014.1.2-0ubuntu1.1 |
| openstack | pycadf | <= 0.5.0 | — |
| openstack | pycadf | — | — |
| openstack | pycadf | — | — |
| openstack | pycadf | — | — |
| openstack | pycadf | — | — |
| openstack | pycadf | — | — |
| openstack | pycadf | — | — |
| openstack | pycadf | — | — |
| openstack | pycadf | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
vendor_ubuntu4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9wrh-vfjh-96rg: The notifier middleware in OpenStack PyCADF 0
ghsa_unreviewed·2022-05-17
CVE-2014-4615 [MEDIUM] CWE-200 GHSA-9wrh-vfjh-96rg: The notifier middleware in OpenStack PyCADF 0
The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).
OSV
neutron vulnerabilities
osv·2014-08-21·CVSS 4.0
CVE-2014-3555 [MEDIUM] neutron vulnerabilities
neutron vulnerabilities
Liping Mao discovered that OpenStack Neutron did not properly handle
requests for a large number of allowed address pairs. A remote
authenticated attacker could exploit this to cause a denial of service.
(CVE-2014-3555)
Zhi Kun Liu discovered that OpenStack Neutron incorrectly filtered certain
tokens. An attacker could possibly use this issue to obtain authentication
tokens used in REST requests. (CVE-2014-4615)
OSV
CVE-2014-4615: The notifier middleware in OpenStack PyCADF 0
osv·2014-08-19·CVSS 5.0
CVE-2014-4615 [MEDIUM] CVE-2014-4615: The notifier middleware in OpenStack PyCADF 0
The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).
Ubuntu
OpenStack Neutron vulnerabilities
vendor_ubuntu·2014-08-21·CVSS 4.0
CVE-2014-3555 [MEDIUM] OpenStack Neutron vulnerabilities
Title: OpenStack Neutron vulnerabilities
Summary: OpenStack Neutron could be made to expose sensitive information or crash.
Liping Mao discovered that OpenStack Neutron did not properly handle
requests for a large number of allowed address pairs. A remote
authenticated attacker could exploit this to cause a denial of service.
(CVE-2014-3555)
Zhi Kun Liu discovered that OpenStack Neutron incorrectly filtered certain
tokens. An attacker could possibly use this issue to obtain authentication
tokens used in REST requests. (CVE-2014-4615)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
OpenStack Ceilometer vulnerability
vendor_ubuntu·2014-08-21
CVE-2014-4615 OpenStack Ceilometer vulnerability
Title: OpenStack Ceilometer vulnerability
Summary: OpenStack Ceilometer could be made to expose sensitive information.
USN-2311-1 fixed vulnerabilities in pyCADF. This update provides the
corresponding updates for OpenStack Ceilometer.
Original advisory details:
Zhi Kun Liu discovered that pyCADF incorrectly filtered certain tokens.
An attacker could possibly use this issue to obtain authentication tokens
used in REST requests.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
pyCADF vulnerability
vendor_ubuntu·2014-08-11
CVE-2014-4615 pyCADF vulnerability
Title: pyCADF vulnerability
Summary: pyCADF could be made to expose sensitive information.
Zhi Kun Liu discovered that pyCADF incorrectly filtered certain tokens.
An attacker could possibly use this issue to obtain authentication tokens
used in REST requests.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
pycadf: token leak to message queue
vendor_redhat·2014-05-20·CVSS 5.0
CVE-2014-4615 [MEDIUM] CWE-201 pycadf: token leak to message queue
pycadf: token leak to message queue
The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).
It was found that authentication tokens were not properly sanitized from the message queue by the notifier middleware. An attacker with read access to the message queue could possibly use this flaw to intercept an authentication token and gain elevated privileges. Note that all services using the notifier middleware configured after the auth_token middleware pipeline were affected.
Package: openstack-ceilometer (Red Hat Enterprise Linux
Debian
CVE-2014-4615: ceilometer - The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilom...
vendor_debian·2014·CVSS 5.0
CVE-2014-4615 [MEDIUM] CVE-2014-4615: ceilometer - The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilom...
The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).
Scope: local
bookworm: resolved (fixed in 2014.1.2-1)
bullseye: resolved (fixed in 2014.1.2-1)
forky: resolved (fixed in 2014.1.2-1)
sid: resolved (fixed in 2014.1.2-1)
trixie: resolved (fixed in 2014.1.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-4615 pycadf: token leak to message queue
bugzilla·2014-06-25·CVSS 5.0
CVE-2014-4615 [MEDIUM] CVE-2014-4615 pycadf: token leak to message queue
CVE-2014-4615 pycadf: token leak to message queue
The OpenStack project reports:
""
Title: User token leak to message queue in pyCADF notifier middleware
Reporter: Zhi Kun Liu (IBM)
Products: Neutron (2014.1 versions up to 2014.1.1)
Ceilometer (2013.2 versions up to 2013.2.3,
2014.1 versions up to 2014.1.1)
pyCADF library (all versions up to 0.5.0)
Description:
Zhi Kun Liu from IBM reported a vulnerability in the notifier middleware
available in the PyCADF library and formerly copied into Neutron and
Ceilometer code. An attacker with read access to the message queue may
obtain authentication tokens used in REST requests (X_AUTH_TOKEN) that
goes through the notifier middleware. All services using the notifier
middleware configured after the auth_token middleware pipeline are impacted.
""
Bugzilla
CVE-2014-4615 python-pycadf: pycadf: token leak to message queue [fedora-20]
bugzilla·2014-06-25·CVSS 5.0
CVE-2014-4615 [MEDIUM] CVE-2014-4615 python-pycadf: pycadf: token leak to message queue [fedora-20]
CVE-2014-4615 python-pycadf: pycadf: token leak to message queue [fedora-20]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
fedora-20 tracking bug for python-p
Bugzilla
CVE-2014-4615 openstack-ceilometer: pycadf: token leak to message queue [fedora-all]
bugzilla·2014-06-25·CVSS 5.0
CVE-2014-4615 [MEDIUM] CVE-2014-4615 openstack-ceilometer: pycadf: token leak to message queue [fedora-all]
CVE-2014-4615 openstack-ceilometer: pycadf: token leak to message queue [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects mu
http://rhn.redhat.com/errata/RHSA-2014-1050.htmlhttp://secunia.com/advisories/60643http://secunia.com/advisories/60736http://secunia.com/advisories/60766http://www.openwall.com/lists/oss-security/2014/06/23/8http://www.openwall.com/lists/oss-security/2014/06/24/6http://www.openwall.com/lists/oss-security/2014/06/25/6http://www.securityfocus.com/bid/68149http://www.ubuntu.com/usn/USN-2311-1http://rhn.redhat.com/errata/RHSA-2014-1050.htmlhttp://secunia.com/advisories/60643http://secunia.com/advisories/60736http://secunia.com/advisories/60766http://www.openwall.com/lists/oss-security/2014/06/23/8http://www.openwall.com/lists/oss-security/2014/06/24/6http://www.openwall.com/lists/oss-security/2014/06/25/6http://www.securityfocus.com/bid/68149http://www.ubuntu.com/usn/USN-2311-1
2014-08-19
Published