First published: Thu Feb 14 2019(Updated: )
A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data to log files without DEBUG logging being activated.
Credit: secalert@redhat.com secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/openstack-ceilometer 10.0.1-6 | <11.0.2 | 11.0.2 |
pip/ceilometer | <12.0.0.0rc1 | 12.0.0.0rc1 |
OpenStack Telemetry (Ceilometer) | <=11.01 | |
OpenStack Telemetry (Ceilometer) | >=2013.1<=2015.1.4 | |
Red Hat OpenStack for IBM Power | =10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3830 is classified as a medium severity vulnerability due to information exposure.
To fix CVE-2019-3830, upgrade to ceilometer version 12.0.0.0rc1 or later, or to openstack-ceilometer version 11.0.2 or later.
CVE-2019-3830 affects OpenStack Telemetry (Ceilometer) versions prior to 12.0.0.0rc1 and openstack-ceilometer versions up to 11.0.2.
CVE-2019-3830 is an Information Exposure vulnerability that allows sensitive data to be logged without DEBUG logging activated.
CVE-2019-3830 may allow attackers to gain insights into sensitive configuration data, making it a potential remote exploitation risk.