PT-2025-23940 · Para · Para

Albogdanopublished

·

Published

2025-06-05

·

Updated

2025-06-06

·

CVE-2025-49009

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Para versions prior to 1.50.8
Description A vulnerability exists in the FacebookAuthFilter.java file, resulting in the full request URL being logged during a failed request to a Facebook user profile. The log includes the user's access token in plain text, posing a risk of token exposure since WARN-level logs are often retained in production and accessible to operators or log aggregation systems.
Recommendations For versions prior to 1.50.8, update to version 1.50.8 to fix the issue. As a temporary workaround, consider restricting access to the logs to minimize the risk of token exposure.

Exploit

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2025-49009
GHSA-QX7G-FX8Q-545G

Affected Products

Para