9.8

CVE-2019-10212

A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Redhat ≫ Undertow Version < 2.0.20
Redhat ≫ Jboss Data Grid Version >= 7.0.0 <= 7.3
Redhat ≫ Jboss Data Grid Version - SwEdition text-only
Redhat ≫ Jboss Enterprise Application Platform Version - SwEdition text-only
Redhat ≫ Jboss Fuse Version >= 7.0.0 <= 7.4
Redhat ≫ Openshift Application Runtimes Version - SwEdition text-only
Redhat ≫ Single Sign-on Version >= 7.0 <= 7.3
Netapp ≫ Active Iq Unified Manager Version - SwPlatform linux
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Netapp ≫ Active Iq Unified Manager Version - SwPlatform windows
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.88% 0.772
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat 4.8 0.5 4.2
CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.

https://access.redhat.com/errata/RHSA-2020:0727
Vendor Advisory
https://access.redhat.com/errata/RHSA-2019:2998
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10212
Vendor Advisory
Issue Tracking
Mitigation
https://security.netapp.com/advisory/ntap-20220210-0017/
Third Party Advisory