{"id":"GHSA-h259-3rjg-5qp3","summary":"Exposure of Sensitive Information to an Unauthorized Actor in JBoss Fuse","details":"JBoss Fuse did not enable encrypted passwords by default in its usage of Apache Zookeeper. This permitted sensitive information disclosure via logging to local users. Note: this description has been updated; previous text mistakenly identified the source of the flaw as Zookeeper. Previous text: Apache Zookeeper logs cleartext admin passwords, which allows local users to obtain sensitive information by reading the log.","aliases":["CVE-2014-0085"],"modified":"2023-11-01T04:45:24.924989Z","published":"2022-05-14T02:19:43Z","database_specific":{"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2022-07-07T23:05:10Z","nvd_published_at":"2014-04-17T14:55:00Z","cwe_ids":["CWE-200"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-0085"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-0085"}],"affected":[{"package":{"name":"org.jboss.fuse:jboss-fuse","ecosystem":"Maven","purl":"pkg:maven/org.jboss.fuse/jboss-fuse"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-h259-3rjg-5qp3/GHSA-h259-3rjg-5qp3.json"}}],"schema_version":"1.9.0"}