CVE-2024-8097
Sensitive information exposure when the org.glassfish.admingui LOGGER is set to FINEST level
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Payara Platform Payara Server (Logging modules) allows Sensitive credentials posted in plain-text on the server log.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.20.0 before 5.67.0, from 5.2020.2 before 5.2022.5, from 4.1.2.191.0 before 4.1.2.191.50.
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Productos afectados
Payara Platform · Payara Server¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →