Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pjw3-c74j-m9fj

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Password in config file in KIE server

It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any app deployed on the same server would have access to these properties, thus granting access to ther services.

Пакеты

Наименование

org.kie.server:kie-server-common

maven
Затронутые версииВерсия исправления

< 7.21.0.Final

7.21.0.Final

EPSS

Процентиль: 53%
0.00298
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-260

Связанные уязвимости

CVSS3: 5.9
redhat
больше 6 лет назад

It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any app deployed on the same server would have access to these properties, thus granting access to ther services.

CVSS3: 5.9
nvd
больше 6 лет назад

It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any app deployed on the same server would have access to these properties, thus granting access to ther services.

EPSS

Процентиль: 53%
0.00298
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-260