SB2019031412 - Red Hat update for openstack-ceilometer
Published: March 14, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2019-3830)
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the ceilometer-agent prints by default sensitive information into log files, even when the DEBUG logging is not activated. A local user can view the log files and obtain sensitive information, such as administrative credentials.
Remediation
Install update from vendor's website.