BIT-wildfly-2020-25640

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/wildfly/BIT-wildfly-2020-25640.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-wildfly-2020-25640
Aliases
Published
2024-03-06T11:09:18.789Z
Modified
2024-03-06T11:25:28.861Z
Summary
[none]
Details

A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in the log file.

References

Affected packages

Bitnami / wildfly

Package

Name
wildfly
Purl
pkg:bitnami/wildfly

Severity

  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
21.0.0