(1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, which allows local users to obtain sensitive information (the DB2 or MongoDB password) by reading the log file.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2013-11-23T18:00:00
Updated: 2024-08-06T17:39:01.251Z
Reserved: 2013-11-04T00:00:00
Link: CVE-2013-6384
Vulnrichment
No data.
NVD
Status : Modified
Published: 2013-11-23T18:55:04.720
Modified: 2024-11-21T01:59:07.300
Link: CVE-2013-6384
Redhat