CVE-2014-9245: Infoleak
Zenoss Core through 5 Beta 3 allows remote attackers to obtain sensitive information by attempting a product-rename action with an invalid new name and then reading a stack trace, as demonstrated by internal URL information, aka ZEN-15382.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9245?
CVE-2014-9245 has a medium severity rating due to potential sensitive information exposure.
How do I fix CVE-2014-9245?
To fix CVE-2014-9245, ensure you are using an updated version of Zenoss Core that addresses this vulnerability.
What can be exploited in CVE-2014-9245?
CVE-2014-9245 can be exploited by remote attackers to obtain sensitive information from stack traces.
Which versions of Zenoss Core are affected by CVE-2014-9245?
CVE-2014-9245 affects Zenoss Core versions up to and including 5 Beta 3 and specific versions from 2.4.0 to 5.0.0.
How does CVE-2014-9245 work?
CVE-2014-9245 allows attackers to trigger a stack trace by attempting a product-rename action with an invalid name.