Information disclosure in Ceilometer - CVE-2019-3830

 

Information disclosure in Ceilometer - CVE-2019-3830

Published: April 1, 2019


Vulnerability identifier: #VU18105
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-3830
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the ceilometer-agent prints by default sensitive information into log files, even when the DEBUG logging is not activated. A local user can view the log files and obtain sensitive information, such as administrative credentials.


Affected software

Ceilometer
Red Hat OpenStack
Red Hat OpenStack for IBM Power

How to mitigate CVE-2019-3830

Install updates from vendor's website.

Ceilometer - update to 12.0.0.0rc1

External References

Related Security Bulletins