UBUNTU-CVE-2014-0085

Source
https://ubuntu.com/security/CVE-2014-0085
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-0085.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2014-0085
Upstream
  • CVE-2014-0085
Published
2014-04-17T14:55:00Z
Modified
2025-09-08T16:43:07Z
Severity
  • Ubuntu - medium
Summary
[none]
Details

JBoss Fuse did not enable encrypted passwords by default in its usage of Apache Zookeeper. This permitted sensitive information disclosure via logging to local users. Note: this description has been updated; previous text mistakenly identified the source of the flaw as Zookeeper. Previous text: Apache Zookeeper logs cleartext admin passwords, which allows local users to obtain sensitive information by reading the log.

References

Affected packages

Ubuntu:Pro:14.04:LTS / zookeeper

Package

Name
zookeeper
Purl
pkg:deb/ubuntu/zookeeper@3.4.5+dfsg-1ubuntu0.1~esm3?arch=source&distro=esm-infra-legacy/trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.4.5+dfsg-1
3.4.5+dfsg-1ubuntu0.1~esm1
3.4.5+dfsg-1ubuntu0.1~esm3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "3.4.5+dfsg-1ubuntu0.1~esm3",
            "binary_name": "libzookeeper-java"
        },
        {
            "binary_version": "3.4.5+dfsg-1ubuntu0.1~esm3",
            "binary_name": "libzookeeper-mt-dev"
        },
        {
            "binary_version": "3.4.5+dfsg-1ubuntu0.1~esm3",
            "binary_name": "libzookeeper-mt2"
        },
        {
            "binary_version": "3.4.5+dfsg-1ubuntu0.1~esm3",
            "binary_name": "libzookeeper-st-dev"
        },
        {
            "binary_version": "3.4.5+dfsg-1ubuntu0.1~esm3",
            "binary_name": "libzookeeper-st2"
        },
        {
            "binary_version": "3.4.5+dfsg-1ubuntu0.1~esm3",
            "binary_name": "libzookeeper2"
        },
        {
            "binary_version": "3.4.5+dfsg-1ubuntu0.1~esm3",
            "binary_name": "python-zookeeper"
        },
        {
            "binary_version": "3.4.5+dfsg-1ubuntu0.1~esm3",
            "binary_name": "zookeeper"
        },
        {
            "binary_version": "3.4.5+dfsg-1ubuntu0.1~esm3",
            "binary_name": "zookeeper-bin"
        },
        {
            "binary_version": "3.4.5+dfsg-1ubuntu0.1~esm3",
            "binary_name": "zookeeperd"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2014/UBUNTU-CVE-2014-0085.json"