SB2019031812 - Red Hat update for openstack-ceilometer
Published: March 18, 2019 Updated: March 18, 2019
Security Bulletin ID
SB2019031812
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Information disclosure
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2019-3830)
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the ceilometer-agent prints by default sensitive information into log files, even when the DEBUG logging is not activated. A local user can view the log files and obtain sensitive information, such as administrative credentials.
Remediation
Install update from vendor's website.