Vulnerability Details CVE-2014-5038
Eucalyptus 3.0.0 through 4.0.1, when the log level is set to DEBUG or lower, logs user and system passwords, which allows local users to obtain sensitive information by reading the cloud log files.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 17.6%
CVSS Severity
CVSS v2 Score 2.1
Products affected by CVE-2014-5038
-
cpe:2.3:a:eucalyptus:eucalyptus:3.0
-
cpe:2.3:a:eucalyptus:eucalyptus:3.0.1
-
cpe:2.3:a:eucalyptus:eucalyptus:3.1.0
-
cpe:2.3:a:eucalyptus:eucalyptus:3.1.1
-
cpe:2.3:a:eucalyptus:eucalyptus:3.1.2
-
cpe:2.3:a:eucalyptus:eucalyptus:3.2.0
-
cpe:2.3:a:eucalyptus:eucalyptus:3.2.1
-
cpe:2.3:a:eucalyptus:eucalyptus:3.2.2
-
cpe:2.3:a:eucalyptus:eucalyptus:3.3.0
-
cpe:2.3:a:eucalyptus:eucalyptus:3.3.1
-
cpe:2.3:a:eucalyptus:eucalyptus:3.3.2
-
cpe:2.3:a:eucalyptus:eucalyptus:3.4.0
-
cpe:2.3:a:eucalyptus:eucalyptus:3.4.1
-
cpe:2.3:a:eucalyptus:eucalyptus:3.4.2
-
cpe:2.3:a:eucalyptus:eucalyptus:3.4.3
-
cpe:2.3:a:eucalyptus:eucalyptus:4.0.0
-
cpe:2.3:a:eucalyptus:eucalyptus:4.0.1