VDB
Sign up
—

PYSEC-2019-78

Quick fix

PYSEC-2019-78 — ceilometer: upgrade to the fixed version with the command below.

pip install --upgrade 'ceilometer>=12.0.0.0rc1'

Details

A vulnerability was found in ceilometer before version 12.0.0.0rc1. An Information Exposure in ceilometer-agent prints sensitive configuration data to log files without DEBUG logging being activated.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/ceilometer
Introduced in: 0Fixed in: 12.0.0.0rc1
Fixpip install --upgrade 'ceilometer>=12.0.0.0rc1'

References