Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Payara Platform Payara Server (Logging modules) allows Sensitive credentials posted in plain-text on the server log.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.20.0 before 5.67.0, from 5.2020.2 before 5.2022.5, from 4.1.2.191.0 before 4.1.2.191.50.
History

Wed, 11 Sep 2024 21:45:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N'}

threat_severity

Moderate


Wed, 11 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 11 Sep 2024 16:45:00 +0000

Type Values Removed Values Added
Description Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Payara Platform Payara Server (Logging modules) allows Sensitive credentials posted in plain-text on the server log.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.20.0 before 5.67.0, from 5.2020.2 before 5.2022.5, from 4.1.2.191.0 before 4.1.2.191.50.
Title Sensitive information exposure when the org.glassfish.admingui LOGGER is set to FINEST level
Weaknesses CWE-200
References
Metrics cvssV4_0

{'score': 6.7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Payara

Published: 2024-09-11T16:32:10.475Z

Updated: 2024-09-11T18:52:51.760Z

Reserved: 2024-08-22T15:06:11.250Z

Link: CVE-2024-8097

cve-icon Vulnrichment

Updated: 2024-09-11T18:52:46.255Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-11T17:15:13.917

Modified: 2024-09-12T12:35:54.013

Link: CVE-2024-8097

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-09-11T17:15:13Z

Links: CVE-2024-8097 - Bugzilla