USN-2311-1 fixed vulnerabilities in pyCADF. This update provides the corresponding updates for OpenStack Ceilometer.
Original advisory details:
Zhi Kun Liu discovered that pyCADF incorrectly filtered certain tokens. An attacker could possibly use this issue to obtain authentication tokens used in REST requests.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "ceilometer-agent-central",
"binary_version": "2014.1.2-0ubuntu1.1"
},
{
"binary_name": "ceilometer-agent-compute",
"binary_version": "2014.1.2-0ubuntu1.1"
},
{
"binary_name": "ceilometer-agent-notification",
"binary_version": "2014.1.2-0ubuntu1.1"
},
{
"binary_name": "ceilometer-alarm-evaluator",
"binary_version": "2014.1.2-0ubuntu1.1"
},
{
"binary_name": "ceilometer-alarm-notifier",
"binary_version": "2014.1.2-0ubuntu1.1"
},
{
"binary_name": "ceilometer-api",
"binary_version": "2014.1.2-0ubuntu1.1"
},
{
"binary_name": "ceilometer-collector",
"binary_version": "2014.1.2-0ubuntu1.1"
},
{
"binary_name": "ceilometer-common",
"binary_version": "2014.1.2-0ubuntu1.1"
},
{
"binary_name": "python-ceilometer",
"binary_version": "2014.1.2-0ubuntu1.1"
}
]
}