CVE-2015-3251
Apache CloudStack before 4.5.2 might allow remote authenticated administrators to obtain sensitive password information for root accounts of virtual machines via unspecified vectors related to API calls.
Date published : 2016-02-08
http://www.securityfocus.com/archive/1/537458/100/0/threaded
https://blogs.apache.org/cloudstack/entry/two_late_announced_security_advisories