The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
Configuration 2 (hide)
| 
 | 
History
                    No history.
Information
                Published : 2014-08-19 18:55
Updated : 2017-01-07 03:00
NVD link : CVE-2014-4615
Mitre link : CVE-2014-4615
CVE.ORG link : CVE-2014-4615
JSON object : View
Products Affected
                openstack
- pycadf
- neutron
- oslo
- telemetry_\(ceilometer\)
canonical
- ubuntu_linux
redhat
- openstack
CWE
                
                    
                        
                        CWE-200
                        
            Exposure of Sensitive Information to an Unauthorized Actor
