CVE-2024-6060

Source
https://cve.org/CVERecord?id=CVE-2024-6060
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-6060.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-6060
Published
2024-06-25T21:36:33.840Z
Modified
2026-07-15T01:49:12.940875743Z
Severity
  • 9.3 (Critical) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/AU:N/R:U/V:C/RE:M/U:Red CVSS Calculator
Summary
[none]
Details

An information disclosure vulnerability in Phloc Webscopes 7.0.0 allows local attackers with access to the log files to view logged HTTP requests that contain user passwords or other sensitive information.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/6xxx/CVE-2024-6060.json",
    "cwe_ids": [
        "CWE-532"
    ],
    "cna_assigner": "Sonatype"
}
References

Affected packages

Git / github.com/phlocbg/phloc-webbasics

Affected ranges

Type
GIT
Repo
https://github.com/phlocbg/phloc-webbasics
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "7.0.0"
        },
        {
            "last_affected": "7.0.0"
        },
        {
            "introduced": "pkg:maven/com.phloc/phloc-webscopes@7.0.0"
        },
        {
            "last_affected": "pkg:maven/com.phloc/phloc-webscopes@7.0.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

7.*
7.0.0
phloc-webscopes-7.*
phloc-webscopes-7.0.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-6060.json"