Release date:
Updated on:
Affected Systems:
Apache Group CloudStack 4.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 57259
CVE (CAN) ID: CVE-2012-5616
Apache CloudStack is an open source software for deploying and managing large virtual machine networks.
Apache CloudStack 4.0.0-incubating and other versions have security vulnerabilities. Local Users can exploit this vulnerability to leak sensitive information.
1) An error exists in the createSSHKeyPair API command. This command stores the new SSH key in the log file, causing key leakage.
2) The AddHost API call records some information in the log file, which may cause leakage of the password of the added host.
3) Call DeployVM and ResetPasswordForVM API records some information in the log file, which may cause leakage of the password of the added VM.
<* Source: Ahmad Emneina (Ahmad Emneina@stratosec.co)
Link: 3C1BD2169F-BBFE-4E27-B50F-F17D7D08B565@stratosec.co % 3E "target =" _ blank "> http://mail-archives.apache.org/mod_mbox/incubator-cloudstack-users/201301.mbox/%3C1BD2169F-BBFE-4E27-B50F-F17D7D08B565@stratosec.co%3E
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://httpd.apache.org/