PT-2024-39724 · Unknown · Quarkus Cxf
Rolf Thorup
·
Published
2024-10-08
·
Updated
2024-12-06
·
CVE-2024-9621
CVSS v4.0
6.0
Medium
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Quarkus CXF (affected versions not specified)
Description
A vulnerability was found in Quarkus CXF where passwords and other secrets may appear in the application log despite the user configuring them to be hidden. This issue requires specific configuration to be vulnerable, such as SOAP logging enabled, application set client, and endpoint logging properties. The attacker must have access to the application log to exploit this issue.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quarkus Cxf