Candidate: CVE-2014-5037 PublicDate: 2014-11-07 19:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5037 https://www.eucalyptus.com/resources/security/advisories/esa-25 http://secunia.com/advisories/62055 Description: Eucalyptus 4.0.0 through 4.0.1, when the log level is set to INFO, logs user and system passwords, which allows local users to obtain sensitive information by reading cloud-requests.log. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_eucalyptus: upstream_eucalyptus: released (4.0.2) lucid_eucalyptus: not-affected precise_eucalyptus: not-affected trusty_eucalyptus: DNE trusty/esm_eucalyptus: DNE utopic_eucalyptus: DNE devel_eucalyptus: DNE