CVE-2019-3830

HIGH

Openstack Ceilometer < 11.01 - Log Information Exposure

Title source: rule

Description

A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data to log files without DEBUG logging being activated.

Scores

CVSS v3 7.8
EPSS 0.0011
EPSS Percentile 30.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-532
Status published

Affected Products (3)

openstack/ceilometer < 11.01
redhat/openstack
pypi/ceilometer < 12.0.0.0rc1PyPI

Timeline

Published Mar 26, 2019
Tracked Since Feb 18, 2026