Inclusion of Sensitive Information in Log Files in Undertow - CVE-2019-10212
Published: October 1, 2019
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists in Undertow DEBUG log implementation for io.undertow.request.security that stored user's credentials in plain text in a world-readable file. A local user can view contents of the debug file and gain access to login and passwords of Undertow users.
Affected software
JBoss Enterprise Application Platform
Opensuse
openEuler
undertow
undertow-javadoc
How to mitigate CVE-2019-10212
JBoss Enterprise Application Platform - update to 7.2.4
undertow - update to 1.4.0-10
undertow-javadoc - update to 1.4.0-10
External References
Related Security Bulletins
- Red Hat update for Red Hat JBoss Enterprise Application Platform 7.2.4 on RHEL 7
- Red Hat update for Red Hat JBoss Enterprise Application Platform 7.2.4 on RHEL 6
- Red Hat update for Red Hat JBoss Enterprise Application Platform 7.2.4
- Red Hat update for Red Hat JBoss Enterprise Application Platform 7.2.4 on RHEL 8
- Red Hat update for Red Hat OpenShift Application Runtimes Thorntail 2.5.0
- OpenSUSE Linux update for SUSE Manager Client Tools
- openEuler update for undertow