Vulnerability Details CVE-2014-5038
Eucalyptus 3.0.0 through 4.0.1, when the log level is set to DEBUG or lower, logs user and system passwords, which allows local users to obtain sensitive information by reading the cloud log files.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 26.9%
CVSS Severity
CVSS v2 Score 2.1
Products affected by CVE-2014-5038
-
cpe:2.3:a:eucalyptus:eucalyptus:3.0
-
cpe:2.3:a:eucalyptus:eucalyptus:3.0.1
-
cpe:2.3:a:eucalyptus:eucalyptus:3.1.0
-
cpe:2.3:a:eucalyptus:eucalyptus:3.1.1
-
cpe:2.3:a:eucalyptus:eucalyptus:3.1.2
-
cpe:2.3:a:eucalyptus:eucalyptus:3.2.0
-
cpe:2.3:a:eucalyptus:eucalyptus:3.2.1
-
cpe:2.3:a:eucalyptus:eucalyptus:3.2.2
-
cpe:2.3:a:eucalyptus:eucalyptus:3.3.0
-
cpe:2.3:a:eucalyptus:eucalyptus:3.3.1
-
cpe:2.3:a:eucalyptus:eucalyptus:3.3.2
-
cpe:2.3:a:eucalyptus:eucalyptus:3.4.0
-
cpe:2.3:a:eucalyptus:eucalyptus:3.4.1
-
cpe:2.3:a:eucalyptus:eucalyptus:3.4.2
-
cpe:2.3:a:eucalyptus:eucalyptus:3.4.3
-
cpe:2.3:a:eucalyptus:eucalyptus:4.0.0
-
cpe:2.3:a:eucalyptus:eucalyptus:4.0.1