CVE-2014-9593: Infoleak
Published Jan 15, 2015
·Updated
Apache CloudStack before 4.3.2 and 4.4.x before 4.4.2 allows remote attackers to obtain private keys via a listSslCerts API call.
Affected Software
3 affected components
Apache CloudStack<=4.3.1
Apache CloudStack=4.4.0
Apache CloudStack=4.4.1
Event History
Jan 15, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9593?
CVE-2014-9593 is classified as a high severity vulnerability because it allows remote attackers to obtain private keys.
2
How do I fix CVE-2014-9593?
To fix CVE-2014-9593, upgrade Apache CloudStack to version 4.3.2 or 4.4.2 or later.
3
What versions of Apache CloudStack are affected by CVE-2014-9593?
CVE-2014-9593 affects Apache CloudStack versions prior to 4.3.2 and 4.4.0 to 4.4.1.
4
What type of attack does CVE-2014-9593 enable?
CVE-2014-9593 enables remote attackers to retrieve private SSL key information via API calls.
5
Is there a workaround for CVE-2014-9593?
There is no known workaround for CVE-2014-9593 apart from installing the appropriate updates.