A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for the database-connection.
Workaround:
Login pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2024:3580 | vendor advisory |
https://access.redhat.com/errata/RHSA-2024:3581 | vendor advisory |
https://access.redhat.com/errata/RHSA-2024:3583 | vendor advisory |
https://access.redhat.com/security/cve/CVE-2024-1102 | vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=2262060 | issue tracking |
https://github.com/jberet/jsr352/issues/452 |