CVE-2014-5038: Infoleak
Published Nov 7, 2014
·Updated
Eucalyptus 3.0.0 through 4.0.1, when the log level is set to DEBUG or lower, logs user and system passwords, which allows local users to obtain sensitive information by reading the cloud log files.
Affected Software
17 affected components
Eucalyptus Eucalyptus=3.0
Eucalyptus Eucalyptus=3.0.1
Eucalyptus Eucalyptus=3.1.0
Eucalyptus Eucalyptus=3.1.1
Eucalyptus Eucalyptus=3.1.2
Eucalyptus Eucalyptus=3.2.0
Eucalyptus Eucalyptus=3.2.1
Eucalyptus Eucalyptus=3.2.2
Eucalyptus Eucalyptus=3.3.0
Eucalyptus Eucalyptus=3.3.1
Eucalyptus Eucalyptus=3.3.2
Eucalyptus Eucalyptus=3.4.0
Eucalyptus Eucalyptus=3.4.1
Eucalyptus Eucalyptus=3.4.2
Eucalyptus Eucalyptus=3.4.3
Eucalyptus Eucalyptus=4.0.0
Eucalyptus Eucalyptus=4.0.1
Remediation
Event History
Nov 7, 2014
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5038?
CVE-2014-5038 has a medium severity rating due to its potential to expose sensitive information.
2
How do I fix CVE-2014-5038?
To fix CVE-2014-5038, update Eucalyptus to version 4.0.2 or later, which addresses the logging issue.
3
What versions of Eucalyptus are affected by CVE-2014-5038?
CVE-2014-5038 affects Eucalyptus versions from 3.0.0 to 4.0.1.
4
What type of information is exposed in CVE-2014-5038?
CVE-2014-5038 exposes user and system passwords in cloud log files.
5
Can local users exploit CVE-2014-5038?
Yes, local users can exploit CVE-2014-5038 by reading the affected log files to obtain sensitive information.