First published: Fri Nov 07 2014(Updated: )
Eucalyptus 4.0.0 through 4.0.1, when the log level is set to INFO, logs user and system passwords, which allows local users to obtain sensitive information by reading cloud-requests.log.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eucalyptus | =4.0.0 | |
Eucalyptus | =4.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-5037 is classified as high due to the exposure of sensitive information such as user and system passwords.
To fix CVE-2014-5037, upgrade Eucalyptus to a version later than 4.0.1, where this logging vulnerability has been addressed.
CVE-2014-5037 affects Eucalyptus versions 4.0.0 and 4.0.1.
CVE-2014-5037 can expose user and system passwords through the logging mechanism in cloud-requests.log.
Yes, local users can exploit CVE-2014-5037 by reading the cloud-requests.log file to obtain sensitive password information.