Candidate: CVE-2014-5038 PublicDate: 2014-11-07 19:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-5038 https://www.eucalyptus.com/resources/security/advisories/esa-26 Description: Eucalyptus 3.0.0 through 4.0.1, when the log level is set to DEBUG or lower, logs user and system passwords, which allows local users to obtain sensitive information by reading the cloud log files. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: Patches_eucalyptus: upstream_eucalyptus: released (4.0.2) lucid_eucalyptus: not-affected precise_eucalyptus: ignored (reached end-of-life) precise/esm_eucalyptus: DNE (precise was needed) trusty_eucalyptus: DNE trusty/esm_eucalyptus: DNE utopic_eucalyptus: DNE vivid_eucalyptus: DNE vivid/stable-phone-overlay_eucalyptus: DNE vivid/ubuntu-core_eucalyptus: DNE wily_eucalyptus: DNE xenial_eucalyptus: DNE yakkety_eucalyptus: DNE zesty_eucalyptus: DNE devel_eucalyptus: DNE