(1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, which allows local users to obtain sensitive information (the DB2 or MongoDB password) by reading the log file.
References
Link Resource
http://www.openwall.com/lists/oss-security/2013/11/22/3 Mailing List Third Party Advisory
http://www.openwall.com/lists/oss-security/2013/11/25/3 Mailing List Third Party Advisory
https://bugs.launchpad.net/ceilometer/+bug/1244476 Exploit Issue Tracking Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2013-11-23T18:00:00

Updated: 2013-12-07T20:57:00

Reserved: 2013-11-04T00:00:00


Link: CVE-2013-6384

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2013-11-23T18:55:04.720

Modified: 2020-10-21T15:13:04.013


Link: CVE-2013-6384

JSON object: View

cve-icon Redhat Information

No data.

CWE