CVE-2019-10212
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.
Affected (13)
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.0.0 to 7.3 | |
| All versions | |
| From 7.0.0 to 7.4 | |
| All versions | |
| From 7.0 to 7.3 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration D
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux | Version 8.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.4 |
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux | Version 7.0 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.2 |
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux | Version 6.0 |
References (8)
Source: secalert@redhat.com
Issue TrackingMitigationVendor Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.