GHSA-jqh2-ch7p-xwxh

Suggest an improvement
Source
https://github.com/advisories/GHSA-jqh2-ch7p-xwxh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/10/GHSA-jqh2-ch7p-xwxh/GHSA-jqh2-ch7p-xwxh.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-jqh2-ch7p-xwxh
Aliases
  • CVE-2024-9621
Published
2024-10-08T18:33:14Z
Modified
2024-12-06T12:49:26.051076Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
  • 6.0 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Quarkus CXF logs passwords and other secrets
Details

A vulnerability was found in Quarkus CXF. Passwords and other secrets may appear in the application log in spite of the user configuring them to be hidden. This issue requires some special configuration to be vulnerable, such as SOAP logging enabled, application set client, and endpoint logging properties, and the attacker must have access to the application log.

Database specific
{
    "nvd_published_at": "2024-10-08T17:15:57Z",
    "cwe_ids": [
        "CWE-532"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-10-08T22:23:11Z"
}
References

Affected packages

Maven / io.quarkiverse.cxf:quarkus-cxf

Package

Name
io.quarkiverse.cxf:quarkus-cxf
View open source insights on deps.dev
Purl
pkg:maven/io.quarkiverse.cxf/quarkus-cxf

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.15.2

Affected versions

0.*

0.1
0.1.0
0.1.1
0.2
0.3
0.4
0.5
0.6
0.7
0.8
0.9
0.10.0
0.11.0
0.12.0
0.13.0
0.13.1
0.14.0

1.*

1.0.0
1.1.0
1.2.0
1.3.0
1.4.0
1.5.0.CR1
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.5.6
1.5.7
1.5.8
1.5.9
1.5.10
1.5.11
1.5.12
1.5.13
1.5.14
1.5.15
1.5.16
1.5.17
1.6.0
1.7.0
1.7.1
1.7.2
1.7.3

2.*

2.0.0.Alpha1
2.0.0.Alpha2
2.0.0.Alpha3
2.0.0.Alpha4
2.0.0.Alpha5
2.0.0.Alpha6
2.0.0.Alpha7
2.0.0.CR1
2.0.0
2.0.1
2.0.2
2.0.3
2.0.4
2.1.0
2.2.0.CR1
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.2.5
2.2.6
2.2.7
2.3.0
2.3.1
2.4.0
2.4.1
2.5.0
2.6.0
2.6.1
2.7.0.CR1
2.7.0.CR2
2.7.0
2.7.1

3.*

3.8.0
3.8.1
3.8.2
3.8.3
3.8.4
3.8.5
3.8.6
3.8.7
3.9.0
3.10.0.CR1
3.10.0
3.11.0
3.11.1
3.12.0.CR1
3.12.0
3.13.0
3.13.1
3.14.0
3.15.0
3.15.1