Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jhf3-ph2m-2vjq

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

(1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, which allows local users to obtain sensitive information (the DB2 or MongoDB password) by reading the log file.

(1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, which allows local users to obtain sensitive information (the DB2 or MongoDB password) by reading the log file.

EPSS

Процентиль: 34%
0.0041
Низкий

Дефекты

CWE-532

Связанные уязвимости

ubuntu
больше 12 лет назад

(1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, which allows local users to obtain sensitive information (the DB2 or MongoDB password) by reading the log file.

redhat
почти 13 лет назад

(1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, which allows local users to obtain sensitive information (the DB2 or MongoDB password) by reading the log file.

nvd
больше 12 лет назад

(1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, which allows local users to obtain sensitive information (the DB2 or MongoDB password) by reading the log file.

debian
больше 12 лет назад

1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 ...

EPSS

Процентиль: 34%
0.0041
Низкий

Дефекты

CWE-532