CVE-2014-5037 describes an information disclosure vulnerability in Eucalyptus versions 4.0.0 through 4.0.1. When the log level is set to INFO, the system logs user and system passwords in the cloud-requests.log file. This allows local attackers to obtain sensitive information by reading the log. The vulnerability has a CVSS score of 2.1 (AV:L/AC:L/Au:N/C:P/I:N/A:N), indicating low severity with local access required for impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.0.0CPE matchmatch criteria | cpe:2.3:a:eucalyptus:eucalyptus:4.0.0:*:*:*:*:*:*:* | ||
4.0.1CPE matchmatch criteria | cpe:2.3:a:eucalyptus:eucalyptus:4.0.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.