CVE Vulnerabilities

CVE-2024-1102

Unprotected Transport of Credentials

Published: Apr 25, 2024 | Modified: Oct 16, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
6.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Ubuntu

A vulnerability was found in jberet-core logging. An exception in dbProperties might display user credentials such as the username and password for the database-connection.

Weakness

Login pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.

Affected Software

Name Vendor Start Version End Version
Red Hat JBoss Enterprise Application Platform 8 RedHat jberet-core *
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 RedHat eap8-hibernate-search-0:6.2.2-1.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 RedHat eap8-jberet-0:2.1.4-1.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 RedHat eap8-hibernate-search-0:6.2.2-1.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 RedHat eap8-jberet-0:2.1.4-1.Final_redhat_00001.1.el9eap *

Potential Mitigations

References