PT-2014-3471 · Red Hat+1 · Jboss Fuse+1
Published
2014-04-17
·
Updated
2022-05-14
·
CVE-2014-0085
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
JBoss Fuse (affected versions not specified)
Description
The issue allows sensitive information disclosure via logging to local users because JBoss Fuse did not enable encrypted passwords by default in its usage of Apache Zookeeper.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Zookeeper
Jboss Fuse