Логотип exploitDog
bind:CVE-2024-40636
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-40636

Количество 2

Количество 2

nvd логотип

CVE-2024-40636

больше 1 года назад

Steeltoe is an open source project that provides a collection of libraries that helps users build production-grade cloud-native applications using externalized configuration, service discovery, distributed tracing, application management, and more. When utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. The code in question is `_logger.LogError(e, "FetchRegistry Failed for Eureka service urls: {EurekaServerServiceUrls}", new Uri(ClientConfig.EurekaServerServiceUrls).ToMaskedString());` in the `DiscoveryClient.cs` file which may leak credentials into logs. This issue has been addressed in version 3.2.8 of the Steeltoe.Discovery.Eureka nuget package.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-vmcp-66r5-3pcp

больше 1 года назад

Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error

CVSS3: 2.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-40636

Steeltoe is an open source project that provides a collection of libraries that helps users build production-grade cloud-native applications using externalized configuration, service discovery, distributed tracing, application management, and more. When utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. The code in question is `_logger.LogError(e, "FetchRegistry Failed for Eureka service urls: {EurekaServerServiceUrls}", new Uri(ClientConfig.EurekaServerServiceUrls).ToMaskedString());` in the `DiscoveryClient.cs` file which may leak credentials into logs. This issue has been addressed in version 3.2.8 of the Steeltoe.Discovery.Eureka nuget package.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-vmcp-66r5-3pcp

Steeltoe Leaks Basic Auth Credentials to Logs After Fetch Registry Error

CVSS3: 2.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу