A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in the log file.
The product generates an error message that includes sensitive information about its environment, users, or associated data.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1881637 | issue tracking vendor advisory |
https://github.com/amqphub/amqp-10-resource-adapter/issues/13 | third party advisory |
https://security.netapp.com/advisory/ntap-20201210-0001/ | third party advisory |