CVE-2019-3830: High severity openstack telemetry (ceilometer) vulnerability

Published Feb 14, 2019
·
Updated

A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data to log files without DEBUG logging being activated.

Other sources

A vulnerability was found in ceilometer. An Information Exposure in ceilometer-agent prints sensitive configuration data to log files without DEBUG logging being activated.

References: https://bugs.launchpad.net/ceilometer/+bug/1811098/

Upstream commit: https://review.openstack.org/#/c/629891/

Red Hat

Affected Software

5 affected componentsFixes available
redhat/openstack-ceilometer 10.0.1-6<11.0.2
11.0.2
pip/ceilometer<12.0.0.0rc1
12.0.0.0rc1
Openstack ceilometer<=11.01
Openstack ceilometer>=2013.1<=2015.1.4
redhat Openstack=10

Event History

Mar 26, 2019
CVE Published
via MITRE·05:55 PM
Data Sourced
via MITRE·05:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
May 13, 2022
Advisory Published
via GitHub·01:14 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2019-3830?

CVE-2019-3830 is classified as a medium severity vulnerability due to information exposure.

2

How do I fix CVE-2019-3830?

To fix CVE-2019-3830, upgrade to ceilometer version 12.0.0.0rc1 or later, or to openstack-ceilometer version 11.0.2 or later.

3

What software is affected by CVE-2019-3830?

CVE-2019-3830 affects OpenStack Telemetry (Ceilometer) versions prior to 12.0.0.0rc1 and openstack-ceilometer versions up to 11.0.2.

4

What type of vulnerability is CVE-2019-3830?

CVE-2019-3830 is an Information Exposure vulnerability that allows sensitive data to be logged without DEBUG logging activated.

5

Is CVE-2019-3830 exploitable remotely?

CVE-2019-3830 may allow attackers to gain insights into sensitive configuration data, making it a potential remote exploitation risk.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203