Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8vh8-vc28-m2hf

Опубликовано: 20 нояб. 2019
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Potential to access user credentials from the log files when debug logging enabled

A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.

Пакеты

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

< 2.0.20

2.0.20

EPSS

Процентиль: 52%
0.0029
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.

CVSS3: 4.8
redhat
больше 6 лет назад

A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.

CVSS3: 9.8
nvd
больше 6 лет назад

A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.

CVSS3: 9.8
debian
больше 6 лет назад

A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for i ...

CVSS3: 9.8
fstec
больше 6 лет назад

Уязвимость компонента io.undertow.request.security веб-сервера Undertow, позволяющая нарушителю получить учетные данные пользователя из файлов журнала

EPSS

Процентиль: 52%
0.0029
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-532