PT-2024-16834 · Unknown · Oauth-Server

Xingxing Xia

·

Published

2024-11-15

·

Updated

2024-11-18

·

CVE-2024-11217

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OAuth-server (affected versions not specified)
Description A weakness was found in the OAuth-server, where it logs the OAuth2 client secret when the logLevel is set to Debug or higher for certain login options, including OIDC, GitHub, GitLab, and Google IDPs.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-11217

Affected Products

Oauth-Server