{"id":"CVE-2014-0085","aliases":[],"url":"https://o3.security/vulnerability/CVE-2014-0085","summary":"Exposure of Sensitive Information to an Unauthorized Actor in JBoss Fuse","details":"JBoss Fuse did not enable encrypted passwords by default in its usage of Apache Zookeeper. This permitted sensitive information disclosure via logging to local users. Note: this description has been updated; previous text mistakenly identified the source of the flaw as Zookeeper. Previous text: Apache Zookeeper logs cleartext admin passwords, which allows local users to obtain sensitive information by reading the log.","published":"2022-05-14T02:19:43Z","modified":"2023-11-08T03:57:31.020919Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.jboss.fuse:jboss-fuse","fixedVersion":"6.1.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-0085"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-0085"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T03:57:31.020919Z"}}