Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4mm4-33wm-56jr

Опубликовано: 02 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 4.5

Описание

System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it requires a backend admin as well as that dbs are locked down by environment.  

OWASP Top 10 - A05) Insecure Design

OWASP Top 10 - A05) Security Misconfiguration

OWASP Top 10 - A09) Security Logging and Monitoring Failure

System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it requires a backend admin as well as that dbs are locked down by environment.  

OWASP Top 10 - A05) Insecure Design

OWASP Top 10 - A05) Security Misconfiguration

OWASP Top 10 - A09) Security Logging and Monitoring Failure

EPSS

Процентиль: 38%
0.00164
Низкий

4.5 Medium

CVSS3

Дефекты

CWE-522
CWE-532

Связанные уязвимости

CVSS3: 4.5
nvd
почти 2 года назад

System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it requires a backend admin as well as that dbs are locked down by environment.   OWASP Top 10 - A05) Insecure Design OWASP Top 10 - A05) Security Misconfiguration OWASP Top 10 - A09) Security Logging and Monitoring Failure

EPSS

Процентиль: 38%
0.00164
Низкий

4.5 Medium

CVSS3

Дефекты

CWE-522
CWE-532