← Back

CVE-2019-10212

nvd nist
Published: Oct 2, 2019Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.

Affected (13)

6 products
Undertow
Jboss Data Grid
Jboss Fuse
Openshift Application Runtimes
Single Sign On
1 product
Active Iq Unified Manager
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 2.0.20
Configuration B
6 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
From 7.0.0 to 7.3
All versions
All versions
From 7.0.0 to 7.4
All versions
From 7.0 to 7.3
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Netapp
All versions
All versions
All versions
Configuration D
1 platform
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 8.0
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 7.4
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 7.0
Configuration F
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Redhat
Version 7.2
Version 7.3
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 6.0

References (8)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Issue TrackingMitigationVendor Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.