CVE-2013-6384: Openstack Ceilometer

Low severity, CVSS 1.9. EPSS: 0.4% chance of exploitation in the next 30 days.

(1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, which allows local users to obtain sensitive information (the DB2 or MongoDB password) by reading the log file.

Affected products

  • Openstack Ceilometer: from 2013.1, up to and including 2013.2

Published 2013-11-23. Last modified 2026-06-17.