CVE Vulnerabilities

CVE-2023-23591

Published: Apr 12, 2023 | Modified: Feb 10, 2025
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs when debug logging is enabled. The fixed versions are 8.2.18.7, 8.2.18.2.2, 8.3.11.1, and 8.3.14.1.

Affected Software

NameVendorStart VersionEnd Version
TerminalfourTerminalfour*8.2.18.2.2 (excluding)
TerminalfourTerminalfour8.2.18.3 (including)8.2.18.7 (excluding)
TerminalfourTerminalfour8.3.0 (including)8.3.11.1 (excluding)
TerminalfourTerminalfour8.3.12 (including)8.3.14.1 (excluding)

References