Lucene search

K
ubuntucveUbuntu.comUB:CVE-2014-0085
HistoryApr 17, 2014 - 12:00 a.m.

CVE-2014-0085

2014-04-1700:00:00
ubuntu.com
ubuntu.com
9

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

0.0004 Low

EPSS

Percentile

5.1%

JBoss Fuse did not enable encrypted passwords by default in its usage of
Apache Zookeeper. This permitted sensitive information disclosure via
logging to local users. Note: this description has been updated; previous
text mistakenly identified the source of the flaw as Zookeeper. Previous
text: Apache Zookeeper logs cleartext admin passwords, which allows local
users to obtain sensitive information by reading the log.

Notes

Author Note
msalvatore Not for us, JBoss Fuse

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

0.0004 Low

EPSS

Percentile

5.1%

Related for UB:CVE-2014-0085