CVE-2014-0085

Impact:
Low
Public Date:
2014-04-14
CWE:
CWE-522
Bugzilla:
1067265: CVE-2014-0085 Fuse: admin user cleartext password appears in logging
JBoss Fuse did not enable encrypted passwords by default in its usage of Apache Zookeeper. This permitted sensitive information disclosure via logging to local users. This issue is a vulnerability in JBoss Fuse's usage of Apache Zookeeper, not in Zookeeper itself as was previously stated.

Find out more about CVE-2014-0085 from the MITRE CVE dictionary dictionary and NIST NVD.

Statement

This flaw only affects Apache Zookeeper in conjunction with Fuse Fabric. Fuse Fabric was storing cleartext passwords, which would appear as cleartext in Apache Zookeeper's log files. Fuse Fabric now encrypts passwords by default.

CVSS v2 metrics

Base Score 2.1
Base Metrics AV:L/AC:L/Au:N/C:P/I:N/A:N
Access Vector Local
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss Fuse 6.1 RHSA-2014:0400 2014-04-14
Red Hat JBoss A-MQ 6.1 RHSA-2014:0401 2014-04-14

Acknowledgements

This issue was discovered by Graeme Colman of Red Hat.

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.