CVE-2019-3830

ceilometer: Insertion of Sensitive Information into Log File (CVE-2019-3830)

Description

A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data to log files without DEBUG logging being activated.

Metrics

Severity
high
no public PoC known
7.8
Source: nvd-v3
32.4 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2019-03-26 17:55 UTC
CWE-532

Weakness classes (CWE)

  • CWE-532Base

    Insertion of Sensitive Information into Log File

    The product writes sensitive information to a log file.

    cwe.mitre.org →

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • openstack

    ceilometer2013.1 – 2015.1.4

  • openstack

    ceilometer11.01

  • redhat

    openstack

References & sources

IDCVE-2019-3830