First published: Tue Jun 24 2014(Updated: )
It was found that the jclouds scriptbuilder Statements class wrote a temporary file to a predictable location. An attacker could use this flaw to access sensitive data, cause a denial of service, or perform other attacks.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apache JClouds | >=1.7.3<1.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4651 has been classified as a medium severity vulnerability.
To fix CVE-2014-4651, upgrade Apache JClouds to version 1.8.0 or later.
CVE-2014-4651 allows attackers to potentially access sensitive data or cause a denial of service.
CVE-2014-4651 affects the Statements class within the Apache JClouds ScriptBuilder module.
CVE-2014-4651 is not relevant for versions of Apache JClouds later than 1.8.0.