7.5
CVE-2019-12399
- EPSS 3.16%
- Published 14.01.2020 15:15:12
- Last modified 21.11.2024 04:22:45
- Source security@apache.org
- Teams watchlist Login
- Open Login
When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration property value, then any client can issue a request to the same Connect cluster to obtain the connector's task configuration and the response will contain the plaintext secret rather than the externalized secrets variables.
Data is provided by the National Vulnerability Database (NVD)
Oracle ≫ Banking Corporate Lending Process Management Version14.1.0
Oracle ≫ Banking Corporate Lending Process Management Version14.3.0
Oracle ≫ Banking Corporate Lending Process Management Version14.4.0
Oracle ≫ Banking Credit Facilities Process Management Version14.1.0
Oracle ≫ Banking Credit Facilities Process Management Version14.3.0
Oracle ≫ Banking Credit Facilities Process Management Version14.4.0
Oracle ≫ Banking Liquidity Management Version >= 14.0.0 <= 14.4.0
Oracle ≫ Banking Payments Version14.4.0
Oracle ≫ Banking Platform Version2.7.0
Oracle ≫ Banking Supply Chain Finance Version >= 14.2.0 <= 14.4.0
Oracle ≫ Banking Trade Finance Process Management Version14.1.0
Oracle ≫ Banking Trade Finance Process Management Version14.3.0
Oracle ≫ Banking Trade Finance Process Management Version14.4.0
Oracle ≫ Banking Virtual Account Management Version14.1.0
Oracle ≫ Banking Virtual Account Management Version14.3.0
Oracle ≫ Banking Virtual Account Management Version14.4.0
Oracle ≫ Blockchain Platform Version < 21.1.2
Oracle ≫ Communications Cloud Native Core Policy Version1.9.0
Oracle ≫ Financial Services Analytical Applications Infrastructure Version >= 8.0.6 <= 8.1.0
Oracle ≫ Flexcube Universal Banking Version14.4.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 3.16% | 0.864 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-319 Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.