Inclusion of Sensitive Information in Log Files in nodejs-firestore - CVE-2023-6460
Published: April 22, 2024
Vulnerability details
The vulnerability allows a local privileged user to gain access to sensitive information.
The vulnerability exists due to software stores sensitive information into log files. A local privileged user can exploit this vulnerability to obtain the firestore key information, and use this information to launch further attacks against the affected system.
Affected software
IBM Maximo Application Suite
How to mitigate CVE-2023-6460
IBM Maximo Application Suite - addressed in versions 8.10.11, 8.11.8