logo

CVE-2014-0085 org.jboss.fuse:jboss-fuse

Package

Manager: maven
Name: org.jboss.fuse:jboss-fuse
Vulnerable Version: >=0 <6.1.0

Severity

Level: Low

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:U/RC:C

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00142 pctl0.3504

Details

Exposure of Sensitive Information to an Unauthorized Actor in JBoss Fuse JBoss Fuse did not enable encrypted passwords by default in its usage of Apache Zookeeper. This permitted sensitive information disclosure via logging to local users. Note: this description has been updated; previous text mistakenly identified the source of the flaw as Zookeeper. Previous text: Apache Zookeeper logs cleartext admin passwords, which allows local users to obtain sensitive information by reading the log.

Metadata

Created: 2022-05-14T02:19:43Z
Modified: 2022-07-07T23:05:10Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-h259-3rjg-5qp3/GHSA-h259-3rjg-5qp3.json
CWE IDs: ["CWE-200"]
Alternative ID: GHSA-h259-3rjg-5qp3
Finding: F038
Auto approve: 1