CVE-2014-4651: Input Validation
It was found that the jclouds scriptbuilder Statements class wrote a temporary file to a predictable location. An attacker could use this flaw to access sensitive data, cause a denial of service, or perform other attacks.
Other sources
JClouds scriptbuilder Statements.java writes a temporary file to a predictable location. An attacker could use this flaw to access sensitive data, denial of service, or other attacks.
http://seclists.org/oss-sec/2014/q2/579 https://issues.apache.org/jira/browse/JCLOUDS-612
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4651?
CVE-2014-4651 has been classified as a medium severity vulnerability.
How do I fix CVE-2014-4651?
To fix CVE-2014-4651, upgrade Apache JClouds to version 1.8.0 or later.
What type of attack can be executed through CVE-2014-4651?
CVE-2014-4651 allows attackers to potentially access sensitive data or cause a denial of service.
What components of Apache JClouds are affected by CVE-2014-4651?
CVE-2014-4651 affects the Statements class within the Apache JClouds ScriptBuilder module.
Is CVE-2014-4651 still relevant for current software versions?
CVE-2014-4651 is not relevant for versions of Apache JClouds later than 1.8.0.