CVE-2014-4615
EPSS 2.8%
描述
The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the message queue (v2/meters/http.request).
如何修補 CVE-2014-4615
要修補 CVE-2014-4615,請將受影響套件升級到下列已修補版本。
- Debian/ceilometer—升級至 2014.1.2-1 或更新版本
- Debian/neutron—升級至 2014.1.2-1 或更新版本
- Debian/python-pycadf—升級至 0.5.1-1 或更新版本
CVE-2014-4615 正在被利用嗎?
低 — EPSS 為 2.8%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < 2014.1.2-1
- from 0, < 2014.1.2-1
- from 0, < 0.5.1-1