CVE Vulnerabilities

CVE-2023-23591

Published: Apr 12, 2023 | Modified: Apr 19, 2023
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs when debug logging is enabled. The fixed versions are 8.2.18.7, 8.2.18.2.2, 8.3.11.1, and 8.3.14.1.

Affected Software

Name Vendor Start Version End Version
Terminalfour Terminalfour * 8.2.18.2.2 (excluding)
Terminalfour Terminalfour 8.2.18.3 (including) 8.2.18.7 (excluding)
Terminalfour Terminalfour 8.3.0 (including) 8.3.11.1 (excluding)
Terminalfour Terminalfour 8.3.12 (including) 8.3.14.1 (excluding)

References