CVE-2014-0085 PUBLISHED

JBoss Fuse did not enable encrypted passwords by default in its usage of Apache Zookeeper. This permitted sensitive information disclosure via logging to local users. Note: this description has been updated; previous text mistakenly identified the source of the flaw as Zookeeper. Previous text: Apache Zookeeper logs cleartext admin passwords, which allows local users to obtain sensitive information by reading the log.

EPSS 0.09% · 24.6th percentile

Risk Scores

EPSS Score
0.09%
24.6th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSzookeeper0, 3.4.5+dfsg-1, 3.4.5+dfsg-1ubuntu0.1~esm1

Timeline

References

Open in Interactive Console →