Bug 1063642 (CVE-2014-0059)

Summary: CVE-2014-0059 JBossSX/PicketBox: World readable audit.log file
Product: [Other] Security Response Reporter: Arun Babu Neelicattu <aneelica>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: anmiller, bdawidow, cdewolf, chaowan, chazlett, grocha, jawilson, jcoleman, jpallich, kconner, kejohnso, lgao, mjc, myarboro, pcheung, pgier, pskopek, pslavice, rsvoboda, security-response-team, sguilhen, spinder, theute, ttarrant, vtunka, weli
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
It was found that the security auditing functionality provided by PicketBox and JBossSX, both security frameworks for Java applications, used a world-readable audit.log file to record sensitive information. A local user could possibly use this flaw to gain access to the sensitive information in the audit.log file.
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-06-08 02:31:33 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1063646, 1063649, 1063650, 1101674, 1101675, 1101676, 1101677, 1101678, 1101679, 1101680, 1101684, 1101685, 1101686, 1101687, 1101688, 1101692, 1101693, 1101694, 1101695, 1101696    
Bug Blocks: 1082938, 1093889, 1139455, 1200191, 1210482    

Description Arun Babu Neelicattu 2014-02-11 07:39:18 UTC
It was identified that security auditing provided by JBossSX/PicketBox logged sensitive information into a world readable audit.log file. This information could be used by a local attacker to gain otherwise protected information about user sessions etc.

Comment 5 errata-xmlrpc 2014-05-27 23:51:31 UTC
This issue has been addressed in following products:

  Red Hat JBoss Enterprise Application Platform 6.2.3

Via RHSA-2014:0565 https://rhn.redhat.com/errata/RHSA-2014-0565.html

Comment 6 errata-xmlrpc 2014-05-27 23:51:44 UTC
This issue has been addressed in following products:

  JBEAP 6.2 for RHEL 6

Via RHSA-2014:0563 https://rhn.redhat.com/errata/RHSA-2014-0563.html

Comment 7 errata-xmlrpc 2014-05-28 00:03:06 UTC
This issue has been addressed in following products:

  JBEAP 6.2 for RHEL 5

Via RHSA-2014:0564 https://rhn.redhat.com/errata/RHSA-2014-0564.html

Comment 8 errata-xmlrpc 2014-07-16 17:12:53 UTC
This issue has been addressed in following products:

  JBoss Data Grid 6.3.0

Via RHSA-2014:0895 https://rhn.redhat.com/errata/RHSA-2014-0895.html

Comment 9 Martin Prpič 2014-07-17 14:34:38 UTC
IssueDescription:

It was found that the security auditing functionality provided by PicketBox and JBossSX, both security frameworks for Java applications, used a world-readable audit.log file to record sensitive information. A local user could possibly use this flaw to gain access to the sensitive information in the audit.log file.

Comment 10 errata-xmlrpc 2014-11-25 16:48:45 UTC
This issue has been addressed in the following products:

  JBoss Operations Network 3.3.0

Via RHSA-2014:1904 https://rhn.redhat.com/errata/RHSA-2014-1904.html

Comment 12 errata-xmlrpc 2015-03-11 16:52:08 UTC
This issue has been addressed in the following products:

JBoss Data Virtualization 6.1.0

Via RHSA-2015:0675 https://rhn.redhat.com/errata/RHSA-2015-0675.html

Comment 13 errata-xmlrpc 2015-04-16 16:04:10 UTC
This issue has been addressed in the following products:

  JBoss BPM Suite 6.1.0

Via RHSA-2015:0851 https://rhn.redhat.com/errata/RHSA-2015-0851.html

Comment 14 errata-xmlrpc 2015-04-16 16:08:44 UTC
This issue has been addressed in the following products:

  JBoss BRMS 6.1.0

Via RHSA-2015:0850 https://rhn.redhat.com/errata/RHSA-2015-0850.html

Comment 15 errata-xmlrpc 2015-05-14 15:15:55 UTC
This issue has been addressed in the following products:

  JBoss Portal 6.2.0

Via RHSA-2015:1009 https://rhn.redhat.com/errata/RHSA-2015-1009.html