CVE Database
/

CVE-2012-5616

Back to search

CVE-2012-5616

Published: Jan 22, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf log file, which allows local users to obtain (1) the SSH private key as recorded by the createSSHKeyPair API, (2) the password of an added host as recorded by the AddHost API, or the password of an added VM as recorded by the (3) DeployVM or (4) ResetPasswordForVM API.

VendorProductVersions

n/a

n/a

affected
n/a

References

89146
vdb-entry
x_refsource_OSVDB
89147
vdb-entry
x_refsource_OSVDB
57225
vdb-entry
x_refsource_BID
51821
third-party-advisory
x_refsource_SECUNIA
57259
vdb-entry
x_refsource_BID
89070
vdb-entry
x_refsource_OSVDB
51366
third-party-advisory
x_refsource_SECUNIA
51827
third-party-advisory
x_refsource_SECUNIA
1027978
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now