PT-2025-23940 · Para · Para

·

CVE-2025-49009

·

Published

2025-06-05

·

Updated

2025-06-06

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Para versions prior to 1.50.8
Description A vulnerability exists in the FacebookAuthFilter.java file, resulting in the full request URL being logged during a failed request to a Facebook user profile. The log includes the user's access token in plain text, posing a risk of token exposure since WARN-level logs are often retained in production and accessible to operators or log aggregation systems.
Recommendations For versions prior to 1.50.8, update to version 1.50.8 to fix the issue. As a temporary workaround, consider restricting access to the logs to minimize the risk of token exposure.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-49009
GHSA-QX7G-FX8Q-545G

Affected Products

Para