VYPR

Oslo

by OpenStack

CVEs (2)

  • CVE-2014-4615Aug 19, 2014
    risk 0.00cvss epss 0.03

    The notifier middleware in OpenStack PyCADF 0.5.0 and earlier, Telemetry (Ceilometer) 2013.2 before 2013.2.4 and 2014.x before 2014.1.2, Neutron 2014.x before 2014.1.2 and Juno before Juno-2, and Oslo allows remote authenticated users to obtain X_AUTH_TOKEN values by reading the…

  • CVE-2013-6491Feb 2, 2014
    risk 0.00cvss epss 0.02

    The python-qpid client (common/rpc/impl_qpid.py) in OpenStack Oslo before 2013.2 does not enforce SSL connections when qpid_protocol is set to ssl, which allows remote attackers to obtain sensitive information by sniffing the network.