USN-2311-1 fixed vulnerabilities in pyCADF. This update provides the corresponding updates for OpenStack Ceilometer.
Original advisory details:
Zhi Kun Liu discovered that pyCADF incorrectly filtered certain tokens. An attacker could possibly use this issue to obtain authentication tokens used in REST requests.
{
"availability": "No subscription required",
"binaries": [
{
"binary_version": "2014.1.2-0ubuntu1.1",
"binary_name": "ceilometer-agent-central"
},
{
"binary_version": "2014.1.2-0ubuntu1.1",
"binary_name": "ceilometer-agent-compute"
},
{
"binary_version": "2014.1.2-0ubuntu1.1",
"binary_name": "ceilometer-agent-notification"
},
{
"binary_version": "2014.1.2-0ubuntu1.1",
"binary_name": "ceilometer-alarm-evaluator"
},
{
"binary_version": "2014.1.2-0ubuntu1.1",
"binary_name": "ceilometer-alarm-notifier"
},
{
"binary_version": "2014.1.2-0ubuntu1.1",
"binary_name": "ceilometer-api"
},
{
"binary_version": "2014.1.2-0ubuntu1.1",
"binary_name": "ceilometer-collector"
},
{
"binary_version": "2014.1.2-0ubuntu1.1",
"binary_name": "ceilometer-common"
},
{
"binary_version": "2014.1.2-0ubuntu1.1",
"binary_name": "python-ceilometer"
}
]
}