Описание
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform 6 | jbossweb | Not affected | ||
| Red Hat JBoss Fuse 6 | undertow | Out of support scope | ||
| Red Hat OpenShift Application Runtimes | undertow | Affected | ||
| Red Hat Process Automation 7 | undertow | Not affected | ||
| Red Hat Data Grid 7.3.3 | undertow | Fixed | RHSA-2020:0727 | 05.03.2020 |
| Red Hat Fuse 7.6.0 | undertow | Fixed | RHSA-2020:0983 | 26.03.2020 |
| Red Hat JBoss EAP 7.2 | Fixed | RHSA-2019:1424 | 10.06.2019 | |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | eap7-apache-commons-codec | Fixed | RHSA-2019:1419 | 10.06.2019 |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | eap7-apache-cxf | Fixed | RHSA-2019:1419 | 10.06.2019 |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | eap7-hal-console | Fixed | RHSA-2019:1419 | 10.06.2019 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)
A vulnerability was found in Undertow web server before 2.0.21. An inf ...
Credential exposure through log files in Undertow
Уязвимость веб-сервера Undertow, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю раскрыть защищаемую информацию
EPSS
5.3 Medium
CVSS3