Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-25640

Опубликовано: 10 сент. 2020
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in the log file.

A flaw was found in wildfly. JMS passwords are logged by the resource adaptor in plain text at the warning level when a connection error occurs allowing any user that has access to the log to gain access to this sensitive information. The highest threat from this vulnerability is to data confidentiality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Data Grid 8wildflyNot affected
Red Hat Decision Manager 7wildflyNot affected
Red Hat JBoss Data Grid 7wildflyOut of support scope
Red Hat JBoss Data Virtualization 6jbossasOut of support scope
Red Hat JBoss Data Virtualization 6wildflyOut of support scope
Red Hat JBoss Enterprise Application Platform 5jbossasOut of support scope
Red Hat JBoss Enterprise Application Platform 6jbossasOut of support scope
Red Hat JBoss Fuse 6wildflyOut of support scope
Red Hat JBoss Operations Network 3wildflyOut of support scope
Red Hat JBoss SOA Platform 5jbossasOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-209
Дефект:
CWE-532
https://bugzilla.redhat.com/show_bug.cgi?id=1881637wildfly: resource adapter logs plaintext JMS password at warning level on connection error

EPSS

Процентиль: 57%
0.00354
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
около 5 лет назад

A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in the log file.

CVSS3: 5.3
debian
около 5 лет назад

A flaw was discovered in WildFly before 21.0.0.Final where, Resource a ...

CVSS3: 5.3
github
почти 4 года назад

Wildfly logs plaintext passwords

EPSS

Процентиль: 57%
0.00354
Низкий

5.3 Medium

CVSS3