PT-2019-5652 · Red Hat · Undertow

Publicado

2019-06-10

·

Atualizado

2022-02-20

·

CVE-2019-3888

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Undertow web server versions prior to 2.0.21
Description The issue is related to insufficient protection of registration data, which can lead to the exposure of protected information. Specifically, the vulnerability allows an attacker to disclose plain text credentials through log files. This occurs because the Connectors.executeRootHandler logs the HttpServerExchange object at the ERROR level using UndertowLogger.REQUEST LOGGER.undertowRequestFailed.
Recommendations For versions prior to 2.0.21, update to version 2.0.21 or later to resolve the issue. As a temporary workaround, consider restricting access to log files to minimize the risk of exploitation.

Correção

XSS

Insertion into Log File

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-04801
BDU:2020-04803
CVE-2019-3888
GHSA-JWGX-9MMH-684W
OESA-2021-1422
RHSA-2019:1419
RHSA-2019:1420
RHSA-2019:1421
RHSA-2019:2439

Produtos afetados

Undertow