Back

MEDIUM

Sensitive information exposure when the org.glassfish.admingui LOGGER is set to FINEST level

Published Sep 11, 2024

Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Payara Platform Payara Server (Logging modules) allows Sensitive credentials posted in plain-text on the server log.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.20.0 before 5.67.0, from 5.2020.2 before 5.2022.5, from 4.1.2.191.0 before 4.1.2.191.50.

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Payara
Published Sep 11, 2024
Updated Sep 11, 2024
Reserved Aug 22, 2024
CISA Vulnrichment
Updated Sep 11, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Sep 11, 2024
ENISA EUVD
Assigner Payara
Published Sep 11, 2024
Updated Sep 11, 2024
Exploited since n/a
EUVD-2024-48937