CyberSec.Space Logo
返回 CVE 浏览器

CVE-2024-3165

MEDIUM
4.5
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2024-04-01
Last Modified2026-06-17
Data SourcesNVD

Vulnerability Description

System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it requires a backend admin as well as that dbs are locked down by environment.   OWASP Top 10 - A05) Insecure Design OWASP Top 10 - A05) Security Misconfiguration OWASP Top 10 - A09) Security Logging and Monitoring Failure

Affected Platforms (CPE)

📦
Dotcms

Dotcms

>= 22.02 and < 22.03.15>= 23.01 and < 23.01.15>= 23.02 and <= 23.09.7= 23.10.24

References & Advisories

相关漏洞威胁