CVE Vulnerabilities

CVE-2024-22339

Insertion of Sensitive Information into Log File

Published: Apr 12, 2024 | Modified: Jan 29, 2025
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

IBM UrbanCode Deploy (UCD) 7.0 through 7.0.5.20, 7.1 through 7.1.2.16, 7.2 through 7.2.3.9, 7.3 through 7.3.2.4 and IBM DevOps Deploy 8.0 through 8.0.0.1 is vulnerable to a sensitive information due to insufficient obfuscation of sensitive values from some log files. IBM X-Force ID: 279979.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
Devops_deployIbm8.0.0.0 (including)8.0.1.0 (excluding)
Urbancode_deployIbm7.0.0.0 (including)7.0.5.21 (excluding)
Urbancode_deployIbm7.1.0.0 (including)7.1.2.17 (excluding)
Urbancode_deployIbm7.2.0.0 (including)7.2.3.10 (excluding)
Urbancode_deployIbm7.3.0.0 (including)7.3.2.5 (excluding)

Potential Mitigations

References