CVE-2019-3830: High severity openstack telemetry (ceilometer) vulnerability
A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data to log files without DEBUG logging being activated.
Other sources
A vulnerability was found in ceilometer. An Information Exposure in ceilometer-agent prints sensitive configuration data to log files without DEBUG logging being activated.
References: https://bugs.launchpad.net/ceilometer/+bug/1811098/
Upstream commit: https://review.openstack.org/#/c/629891/
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3830?
CVE-2019-3830 is classified as a medium severity vulnerability due to information exposure.
How do I fix CVE-2019-3830?
To fix CVE-2019-3830, upgrade to ceilometer version 12.0.0.0rc1 or later, or to openstack-ceilometer version 11.0.2 or later.
What software is affected by CVE-2019-3830?
CVE-2019-3830 affects OpenStack Telemetry (Ceilometer) versions prior to 12.0.0.0rc1 and openstack-ceilometer versions up to 11.0.2.
What type of vulnerability is CVE-2019-3830?
CVE-2019-3830 is an Information Exposure vulnerability that allows sensitive data to be logged without DEBUG logging activated.
Is CVE-2019-3830 exploitable remotely?
CVE-2019-3830 may allow attackers to gain insights into sensitive configuration data, making it a potential remote exploitation risk.