PT-2025-23499 · Para · Para
Albogdanopublished
·
Published
2025-05-30
·
Updated
2025-06-02
·
CVE-2025-48955
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Para versions prior to 1.50.8
Description
A vulnerability exists in Para, a multitenant backend server/framework for object persistence and retrieval, which exposes both access and secret keys in logs without redaction. These credentials are later reused in variable assignments for persistence but do not require logging for debugging or system health purposes.
Recommendations
For versions prior to 1.50.8, update to version 1.50.8 to fix the issue. As a temporary workaround, consider restricting log access to minimize the risk of credential exposure. Avoid logging access and secret keys for debugging or system health purposes until the issue is resolved.
Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Para