Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jwgx-9mmh-684w

Опубликовано: 13 июн. 2019
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Credential exposure through log files in Undertow

A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)

Пакеты

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

< 2.0.21

2.0.21

EPSS

Процентиль: 68%
0.00569
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 6 лет назад

A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)

CVSS3: 5.3
redhat
больше 6 лет назад

A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)

CVSS3: 9.8
nvd
больше 6 лет назад

A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)

CVSS3: 9.8
debian
больше 6 лет назад

A vulnerability was found in Undertow web server before 2.0.21. An inf ...

CVSS3: 5.3
fstec
больше 6 лет назад

Уязвимость веб-сервера Undertow, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 68%
0.00569
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-532