Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2012-5616

Опубликовано: 22 янв. 2013
Источник: nvd
CVSS2: 1.5
EPSS Низкий

Описание

Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf log file, which allows local users to obtain (1) the SSH private key as recorded by the createSSHKeyPair API, (2) the password of an added host as recorded by the AddHost API, or the password of an added VM as recorded by the (3) DeployVM or (4) ResetPasswordForVM API.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:apache:cloudstack:4.0.0:incubating:*:*:*:*:*:*
cpe:2.3:a:citrix:cloudplatform:*:*:*:*:*:*:*:*
Версия до 3.0.5 (включая)

EPSS

Процентиль: 36%
0.0015
Низкий

1.5 Low

CVSS2

Дефекты

CWE-255

Связанные уязвимости

github
больше 3 лет назад

Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf log file, which allows local users to obtain (1) the SSH private key as recorded by the createSSHKeyPair API, (2) the password of an added host as recorded by the AddHost API, or the password of an added VM as recorded by the (3) DeployVM or (4) ResetPasswordForVM API.

EPSS

Процентиль: 36%
0.0015
Низкий

1.5 Low

CVSS2

Дефекты

CWE-255