#VU18105 Information disclosure in Ceilometer - CVE-2019-3830
Published: April 1, 2019
Ceilometer
Openstack
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the ceilometer-agent prints by default sensitive information into log files, even when the DEBUG logging is not activated. A local user can view the log files and obtain sensitive information, such as administrative credentials.