CVE Vulnerabilities

CVE-2024-1102

Unprotected Transport of Credentials

Published: Apr 25, 2024 | Modified: Oct 24, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Ubuntu
root.io logo minimus.io logo echo.ai logo

A vulnerability was found in jberet-core logging. An exception in dbProperties might display user credentials such as the username and password for the database-connection.

Weakness

Login pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.

Affected Software

NameVendorStart VersionEnd Version
JberetJberet*2.2.1 (excluding)
Red Hat JBoss Enterprise Application PlatformRedHatorg.jberet/jberet-core:1.3.9.SP3-redhat-00001*
Red Hat JBoss Enterprise Application Platform 8RedHatjberet-core*
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8RedHateap8-hibernate-search-0:6.2.2-1.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8RedHateap8-jberet-0:2.1.4-1.Final_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9RedHateap8-hibernate-search-0:6.2.2-1.Final_redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9RedHateap8-jberet-0:2.1.4-1.Final_redhat_00001.1.el9eap*

Potential Mitigations

References