Описание
A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data to log files without DEBUG logging being activated.
A vulnerability was found in ceilometer where administrative credentials were permanently stored in the log. A user with access to the logs could obtain these credentials and escalate their privileges.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenStack Platform 15 (Stein) | openstack-ceilometer | Not affected | ||
| Red Hat OpenStack Platform 8 (Liberty) | openstack-ceilometer | Not affected | ||
| Red Hat OpenStack Platform 9 (Mitaka) | openstack-ceilometer | Not affected | ||
| Red Hat OpenStack Platform 10.0 (Newton) | openstack-ceilometer | Fixed | RHSA-2019:0919 | 30.04.2019 |
| Red Hat OpenStack Platform 13.0 (Queens) | openstack-ceilometer | Fixed | RHSA-2019:0566 | 14.03.2019 |
| Red Hat OpenStack Platform 14.0 (Rocky) | openstack-ceilometer | Fixed | RHSA-2019:0580 | 18.03.2019 |
Показывать по
Дополнительная информация
Статус:
EPSS
4 Medium
CVSS3
Связанные уязвимости
A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data to log files without DEBUG logging being activated.
A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data to log files without DEBUG logging being activated.
A vulnerability was found in ceilometer before version 12.0.0.0rc1. An ...
Ceilometer Prints Sensitive Configuration Data to Log
EPSS
4 Medium
CVSS3