CVE-2014-5037: Infoleak
Published Nov 7, 2014
·Updated
Eucalyptus 4.0.0 through 4.0.1, when the log level is set to INFO, logs user and system passwords, which allows local users to obtain sensitive information by reading cloud-requests.log.
Affected Software
2 affected components
Eucalyptus Eucalyptus=4.0.0
Eucalyptus Eucalyptus=4.0.1
Remediation
Event History
Nov 7, 2014
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5037?
The severity of CVE-2014-5037 is classified as high due to the exposure of sensitive information such as user and system passwords.
2
How do I fix CVE-2014-5037?
To fix CVE-2014-5037, upgrade Eucalyptus to a version later than 4.0.1, where this logging vulnerability has been addressed.
3
What versions of Eucalyptus are affected by CVE-2014-5037?
CVE-2014-5037 affects Eucalyptus versions 4.0.0 and 4.0.1.
4
What type of information can be compromised by CVE-2014-5037?
CVE-2014-5037 can expose user and system passwords through the logging mechanism in cloud-requests.log.
5
Can local users exploit CVE-2014-5037?
Yes, local users can exploit CVE-2014-5037 by reading the cloud-requests.log file to obtain sensitive password information.