Sensitive information exposure when the org.glassfish.admingui LOGGER is set to FINEST level
Published Sep 11, 2024
6.7
MEDIUMCVSS 4.0
EPSS 0.19%
Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Payara Platform Payara Server (Logging modules) allows Sensitive credentials posted in plain-text on the server log.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.20.0 before 5.67.0, from 5.2020.2 before 5.2022.5, from 4.1.2.191.0 before 4.1.2.191.50.
Affected products
-
- Version 4.1.2.191.0StatusaffectedConstraints<4.1.2.191.50
- Version 5.20.0StatusaffectedConstraints<5.67.0
- Version 5.2020.2StatusaffectedConstraints<5.2022.5
- Version 6.0.0StatusaffectedConstraints<6.18.0
- Version 6.2022.1StatusaffectedConstraints<6.2024.9
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Payara Platform | Payara Server | unaffected |
|
No data.
No data.
Red Hat JBoss Data Grid 7
fish.payara.arquillian/arquillian-payara-server-4-managed
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Data Grid 7 | fish.payara.arquillian/arquillian-payara-server-4-managed | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (7)
- https://access.redhat.com/security/cve/CVE-2024-8097 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2311758 Issue Tracking
- https://docs.payara.fish/community/docs/Release%20Notes/Release%20Notes%206.2024.9.html release-notes
- https://docs.payara.fish/enterprise/docs/Release%20Notes/Release%20Notes%206.18.0.html release-notes
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-48937 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-8097
- https://www.cve.org/CVERecord?id=CVE-2024-8097
Change history (0)
No recorded changes yet.