CVE-2019-3830Log File Information Exposure in Ceilometer

Severity
7.8HIGHNVD
EPSS
0.1%
top 69.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 26
Latest updateMay 13

Description

A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data to log files without DEBUG logging being activated.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages4 packages

PyPIopenstack/ceilometer< 12.0.0.0rc1
Debianopenstack/ceilometer< 1:11.0.1-5+3
NVDopenstack/ceilometer2013.12015.1.4+1

Patches

🔴Vulnerability Details

4
OSV
Ceilometer Prints Sensitive Configuration Data to Log2022-05-13
GHSA
Ceilometer Prints Sensitive Configuration Data to Log2022-05-13
OSV
CVE-2019-3830: A vulnerability was found in ceilometer before version 122019-03-26
CVEList
CVE-2019-3830: A vulnerability was found in ceilometer before version 122019-03-26

📋Vendor Advisories

2
Red Hat
openstack-ceilometer: ceilometer-agent prints sensitive data from config files through log files2019-01-09
Debian
CVE-2019-3830: ceilometer - A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Informati...2019

💬Community

2
Bugzilla
CVE-2019-3830 openstack-ceilometer: ceilometer-agent prints sensitive data from config files through log files [openstack-rdo]2019-03-19
Bugzilla
CVE-2019-3830 openstack-ceilometer: ceilometer-agent prints sensitive data from config files through log files2019-02-14
CVE-2019-3830 — Log File Information Exposure | cvebase