REDHAT-BUG-1067265: Low severity red hat fuse vulnerability
Graeme Colman of Red Hat reported a sensitive data exposure flaw in Apache Zookeeper. An admin user's password appeared in plaintext in binary log files. A local user could read this information and use it to gain administrative access to the application.
Update 2018-08-06:
JBoss Fuse did not enable encrypted passwords by default in its usage of Apache Zookeeper. This permitted sensitive information disclosure via logging to local users. This issue is a vulnerability in JBoss Fuse's usage of Apache Zookeeper, not in Zookeeper itself as was previously stated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1067265?
The severity of REDHAT-BUG-1067265 is critical due to sensitive data exposure that allows unauthorized access to admin credentials.
How do I fix REDHAT-BUG-1067265?
To fix REDHAT-BUG-1067265, you should update to the latest version of Apache Zookeeper or Red Hat JBoss Fuse that addresses this vulnerability.
What type of vulnerability is REDHAT-BUG-1067265?
REDHAT-BUG-1067265 is classified as a sensitive data exposure vulnerability, specifically exposing admin user passwords in plaintext.
Who reported REDHAT-BUG-1067265?
REDHAT-BUG-1067265 was reported by Graeme Colman of Red Hat.
How does REDHAT-BUG-1067265 affect system security?
REDHAT-BUG-1067265 allows local users to read admin passwords from binary log files, potentially leading to unauthorized administrative access.