Bug 1072716 (CVE-2014-0121)
Summary: | CVE-2014-0121 hawtio-karaf-terminal: remote code execution due to missing authentication | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Trevor Jay <tjay> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED CURRENTRELEASE | QA Contact: | |
Severity: | urgent | Docs Contact: | |
Priority: | urgent | ||
Version: | unspecified | CC: | chazlett, djorm, jrusnack, security-response-team, weli |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2014-04-14 18:43:19 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 1072724 |
Description
Trevor Jay
2014-03-05 05:18:24 UTC
Acknowledgements: This issue was discovered by David Jorm of the Red Hat Security Response Team. Upstream patch commits: https://github.com/hawtio/hawtio/commit/5289715e4f2657562fdddcbad830a30969b96e1e https://github.com/hawtio/hawtio/commit/bedbba03dd971d481a6852ccdaec670a9665e94b Statement: Not vulnerable. This issue only affects Red Hat JBoss Fuse 6.1.0 Beta. It is resolved in the general availability release of Red Hat JBoss Fuse 6.1.0. Earlier versions of Red Hat JBoss Fuse are not affected, as they did not include the hawtio-karaf-terminal component. |