PT-2023-23124 · Cloverdx · Cloverdx

Branislav Repcek

·

Published

2023-04-24

·

Updated

2023-04-29

·

CVE-2023-31056

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions CloverDX versions prior to 5.15.4 CloverDX versions prior to 5.16.2 CloverDX versions prior to 5.17.3 CloverDX versions prior to 6.0.x
Description The issue arises when CloverDX writes passwords to the audit log under certain conditions, specifically if the audit log is enabled and single sign-on is not used.
Recommendations For versions prior to 5.15.4, update to version 5.15.4 or later. For versions prior to 5.16.2, update to version 5.16.2 or later. For versions prior to 5.17.3, update to version 5.17.3 or later. For versions prior to 6.0.x, update to version 6.0.x or later.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-31056

Affected Products

Cloverdx