ossa/ossa/OSSA-2014-021.yaml

66 lines
1.5 KiB
YAML

date: 2014-06-25
id: OSSA-2014-021
title: 'User token leak to message queue in pyCADF notifier middleware'
description: 'Zhi Kun Liu from IBM reported a vulnerability in the notifier middleware
available in the PyCADF library and formerly copied into Neutron and Ceilometer
code. An attacker with read access to the message queue may obtain authentication
tokens used in REST requests (X_AUTH_TOKEN) that goes through the notifier middleware.
All services using the notifier middleware configured after the auth_token middleware
pipeline are impacted.'
reference: http://lists.openstack.org/pipermail/openstack-announce/2014-June/000245.html
affected-products:
- product: neutron
version: 2014.1 versions up to 2014.1.1
- product: ceilometer
version: 2013.2 versions up to 2013.2.3, 2014.1 versions up to 2014.1.1
vulnerabilities:
- cve-id: CVE-2014-4615
impact-assessment:
source: 'Red Hat Product Security'
rating: important
assessment:
type: CVSS2
score: 5.0
detail: AV:N/AC:L/Au:N/C:P/I:N/A:N
classification:
source: 'Red Hat Product Security'
type: CWE
detail: TODO
reporters:
- name: 'Zhi Kun Liu'
affiliation: IBM
reported:
- CVE-2014-4615
issues:
links:
- https://launchpad.net/bugs/1321080
type: launchpad
reviews:
juno:
- https://review.openstack.org/#/c/94891
icehouse:
- https://review.openstack.org/#/c/101097
- https://review.openstack.org/#/c/96944
havana:
- https://review.openstack.org/#/c/101799
type: gerrit