Impact
Boruta, an OAuth 2.0 and OpenID Connect authorization server, logged highly sensitive authentication artifacts, including access tokens, refresh tokens, authorization codes, and various identity tokens, in its business event logs. This flaw meant that any attacker who could read these logs had access to usable credentials until they expired or were revoked, thereby compromising integrity and confidentiality of protected resources. The weakness is classified as CWE‑532, indicating insecure storage of credentials in logs.
Affected Systems
The vulnerability affects the malach‑it:boruta‑server product on all releases prior to version 0.10.0. Users running versions older than 0.10.0 are at risk until they upgrade.
Risk and Exploitability
The CVSS score of 6.5 places this flaw in the medium severity range. EPSS data is not available, but the vulnerability is not listed in the CISA KEV catalog. The attack requires an adversary with visibility into Boruta's logs, which could be gained through log aggregation systems, administrator log viewers, or similar access points. Consequently, privileged or compromised users who can access logs could exploit the exposed tokens to impersonate legitimate clients or end users, potentially leading to unauthorized data access or service disruption. The risk is heightened if log storage or transmission mechanisms lack proper access controls.
OpenCVE Enrichment