The Storage Controller (SC) component in Eucalyptus 3.4.2 through 4.0.x before 4.0.1, when Dell Equallogic SAN is used, logs the CHAP user credentials, which allows local users to obtain sensitive information by reading the logs.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://secunia.com/advisories/60359 | third party advisory |
http://secunia.com/advisories/60712 | third party advisory |
https://www.eucalyptus.com/resources/security/advisories/esa-23 | vendor advisory |