Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-6384

Опубликовано: 23 нояб. 2013
Источник: nvd
CVSS2: 1.9
EPSS Низкий

Описание

(1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, which allows local users to obtain sensitive information (the DB2 or MongoDB password) by reading the log file.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:openstack:ceilometer:*:*:*:*:*:*:*:*
Версия от 2013.1 (включая) до 2013.2 (включая)

EPSS

Процентиль: 18%
0.00057
Низкий

1.9 Low

CVSS2

Дефекты

CWE-532

Связанные уязвимости

ubuntu
около 12 лет назад

(1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, which allows local users to obtain sensitive information (the DB2 or MongoDB password) by reading the log file.

redhat
около 12 лет назад

(1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, which allows local users to obtain sensitive information (the DB2 or MongoDB password) by reading the log file.

debian
около 12 лет назад

1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 ...

github
больше 3 лет назад

(1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, which allows local users to obtain sensitive information (the DB2 or MongoDB password) by reading the log file.

EPSS

Процентиль: 18%
0.00057
Низкий

1.9 Low

CVSS2

Дефекты

CWE-532