Jberet: jberet-core logging database credentials
Published Apr 25, 2024
6.5
MEDIUMCVSS 3.1
EPSS 0.79%
Description
A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for the database-connection.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | affected |
|
Configuration 2
- n/a
- 8.0
No data.
Red Hat JBoss Enterprise Application Platform
org.jberet/jberet-core:1.3.9.SP3-redhat-00001
Fixed · RHSA-2024:1677
Red Hat JBoss Enterprise Application Platform 8
jberet-core
Fixed · RHSA-2024:3583
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
eap8-hibernate-search-0:6.2.2-1.Final_redhat_00001.1.el8eap
Fixed · RHSA-2024:3580
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8
eap8-jberet-0:2.1.4-1.Final_redhat_00001.1.el8eap
Fixed · RHSA-2024:3580
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
eap8-hibernate-search-0:6.2.2-1.Final_redhat_00001.1.el9eap
Fixed · RHSA-2024:3581
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9
eap8-jberet-0:2.1.4-1.Final_redhat_00001.1.el9eap
Fixed · RHSA-2024:3581
Red Hat Build of Keycloak
jberet-core
Not affected
Red Hat Data Grid 8
jberet-core
Not affected
Red Hat Fuse 7
jberet-core
Out of support scope
Red Hat JBoss Data Grid 7
jberet-core
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
jberet-core
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
keycloak-adapter-eap6
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
keycloak-adapter-sso7_2-eap6
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
keycloak-adapter-sso7_3-eap6
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
keycloak-adapter-sso7_4-eap6
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
keycloak-adapter-sso7_5-eap6
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
org.keycloak-keycloak-parent
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
rh-sso7-keycloak
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
jberet-core
Affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
jberet-core
Not affected
Red Hat Single Sign-On 7
jberet-core
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform | org.jberet/jberet-core:1.3.9.SP3-redhat-00001 | Fixed | RHSA-2024:1677 |
| Red Hat JBoss Enterprise Application Platform 8 | jberet-core | Fixed | RHSA-2024:3583 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-hibernate-search-0:6.2.2-1.Final_redhat_00001.1.el8eap | Fixed | RHSA-2024:3580 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | eap8-jberet-0:2.1.4-1.Final_redhat_00001.1.el8eap | Fixed | RHSA-2024:3580 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | eap8-hibernate-search-0:6.2.2-1.Final_redhat_00001.1.el9eap | Fixed | RHSA-2024:3581 |
| Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | eap8-jberet-0:2.1.4-1.Final_redhat_00001.1.el9eap | Fixed | RHSA-2024:3581 |
| Red Hat Build of Keycloak | jberet-core | Not affected | n/a |
| Red Hat Data Grid 8 | jberet-core | Not affected | n/a |
| Red Hat Fuse 7 | jberet-core | Out of support scope | n/a |
| Red Hat JBoss Data Grid 7 | jberet-core | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | jberet-core | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | keycloak-adapter-eap6 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | keycloak-adapter-sso7_2-eap6 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | keycloak-adapter-sso7_3-eap6 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | keycloak-adapter-sso7_4-eap6 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | keycloak-adapter-sso7_5-eap6 | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | org.keycloak-keycloak-parent | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | rh-sso7-keycloak | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jberet-core | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | jberet-core | Not affected | n/a |
| Red Hat Single Sign-On 7 | jberet-core | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Apr 25, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (6 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.79% (0.00788) | 54.64th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.79% (0.00788) | 51.21th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.31% (0.00314) | 52.32th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00044) | 12.15th | v3 (v2023.03.01) |
| Jun 6, 2024 | 0.04% (0.00044) | 10.10th | v3 (v2023.03.01) |
| Apr 26, 2024 | 0.04% (0.00045) | 14.14th | v3 (v2023.03.01) |
References (11)
- https://access.redhat.com/errata/RHSA-2024:1677 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:3580 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:3581 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2024:3583 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2024-1102 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2262060 issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://github.com/advisories/GHSA-9wmf-xf3h-r8pr Advisory
- https://github.com/jberet/jsr352/commit/eeef999663d7da0e372aeeeac26ecf7201a3121d
- https://github.com/jberet/jsr352/issues/452 ExploitIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2024-1102
- https://www.cve.org/CVERecord?id=CVE-2024-1102
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2024:1677 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2024:3580 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2024:3581 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/errata/RHSA-2024:3583 | vendor-advisoryx_refsource_REDHATThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2024-1102 | vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2262060 | issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory | |
| https://github.com/advisories/GHSA-9wmf-xf3h-r8pr | Advisory | |
| https://github.com/jberet/jsr352/commit/eeef999663d7da0e372aeeeac26ecf7201a3121d | ||
| https://github.com/jberet/jsr352/issues/452 | ExploitIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2024-1102 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-1102 |
Change history (0)
No recorded changes yet.