CVE-2012-5616 describes a sensitive information disclosure vulnerability affecting Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before version 3.0.6. The flaw allows local, authenticated users to retrieve SSH private keys and various passwords from the log4j.conf log file, which are recorded by several API calls such as createSSHKeyPair, AddHost, DeployVM, and ResetPasswordForVM. With a CVSS score of 1.5, this vulnerability has a low severity, requiring local access and medium attack complexity to achieve partial confidentiality impact. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0.0CPE matchmatch criteria | cpe:2.3:a:apache:cloudstack:4.0.0:incubating:*:*:*:*:*:* | ||
<= 3.0.5CPE matchmatch criteria | cpe:2.3:a:citrix:cloudplatform:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:S/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.