Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-6384

Опубликовано: 23 нояб. 2013
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 1.9

Описание

(1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, which allows local users to obtain sensitive information (the DB2 or MongoDB password) by reading the log file.

РелизСтатусПримечание
devel

not-affected

esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected]
lucid

DNE

precise

DNE

quantal

ignored

end of life
raring

ignored

end of life
saucy

not-affected

2013.2.3-0ubuntu1
trusty

not-affected

trusty/esm

DNE

trusty was not-affected
upstream

needs-triage

Показывать по

EPSS

Процентиль: 18%
0.00057
Низкий

1.9 Low

CVSS2

Связанные уязвимости

redhat
около 12 лет назад

(1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, which allows local users to obtain sensitive information (the DB2 or MongoDB password) by reading the log file.

nvd
около 12 лет назад

(1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, which allows local users to obtain sensitive information (the DB2 or MongoDB password) by reading the log file.

debian
около 12 лет назад

1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 ...

github
больше 3 лет назад

(1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, which allows local users to obtain sensitive information (the DB2 or MongoDB password) by reading the log file.

EPSS

Процентиль: 18%
0.00057
Низкий

1.9 Low

CVSS2