Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8 in `FacebookAuthFilter.java` results in a full request URL being logged during a failed request to a Facebook user profile. The log includes the user's access token in plain text. Since WARN-level logs are often retained in production and accessible to operators or log aggregation systems, this poses a risk of token exposure. Version 1.50.8 fixes the issue.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-17008 Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8 in `FacebookAuthFilter.java` results in a full request URL being logged during a failed request to a Facebook user profile. The log includes the user's access token in plain text. Since WARN-level logs are often retained in production and accessible to operators or log aggregation systems, this poses a risk of token exposure. Version 1.50.8 fixes the issue.
Github GHSA Github GHSA GHSA-qx7g-fx8q-545g Para Inserts Sensitive Information into Log File for Facebook authentication
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 17 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Jun 2025 17:00:00 +0000

Type Values Removed Values Added
Description Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8 in `FacebookAuthFilter.java` results in a full request URL being logged during a failed request to a Facebook user profile. The log includes the user's access token in plain text. Since WARN-level logs are often retained in production and accessible to operators or log aggregation systems, this poses a risk of token exposure. Version 1.50.8 fixes the issue.
Title Para Inserts Sensitive Information into Log File for Facebook authentication
Weaknesses CWE-532
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-06-17T13:54:23.657Z

Reserved: 2025-05-29T16:34:07.176Z

Link: CVE-2025-49009

cve-icon Vulnrichment

Updated: 2025-06-17T13:54:17.098Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-05T17:15:29.570

Modified: 2025-06-05T20:12:23.777

Link: CVE-2025-49009

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-06-20T13:55:53Z