PT-2024-39724 · Unknown · Quarkus Cxf

Rolf Thorup

·

Published

2024-10-08

·

Updated

2024-12-06

·

CVE-2024-9621

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Quarkus CXF (affected versions not specified)
Description A vulnerability was found in Quarkus CXF where passwords and other secrets may appear in the application log despite the user configuring them to be hidden. This issue requires specific configuration to be vulnerable, such as SOAP logging enabled, application set client, and endpoint logging properties. The attacker must have access to the application log to exploit this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2024-9621
GHSA-JQH2-CH7P-XWXH

Affected Products

Quarkus Cxf