PT-2019-5652 · Red Hat · Undertow

Published

2019-06-10

·

Updated

2022-02-20

·

CVE-2019-3888

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Undertow web server versions prior to 2.0.21
Description The issue is related to insufficient protection of registration data, which can lead to the exposure of protected information. Specifically, the vulnerability allows an attacker to disclose plain text credentials through log files. This occurs because the Connectors.executeRootHandler logs the HttpServerExchange object at the ERROR level using UndertowLogger.REQUEST LOGGER.undertowRequestFailed.
Recommendations For versions prior to 2.0.21, update to version 2.0.21 or later to resolve the issue. As a temporary workaround, consider restricting access to log files to minimize the risk of exploitation.

Fix

XSS

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04801
BDU:2020-04803
CVE-2019-3888
GHSA-JWGX-9MMH-684W
OESA-2021-1422
RHSA-2019:1419
RHSA-2019:1420
RHSA-2019:1421
RHSA-2019:2439

Affected Products

Undertow