CVE Vulnerabilities

CVE-2024-3165

Insertion of Sensitive Information into Log File

Published: Apr 01, 2024 | Modified: Jun 27, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it requires a backend admin as well as that dbs are locked down by environment.  

OWASP Top 10 - A05) Insecure Design

OWASP Top 10 - A05) Security Misconfiguration

OWASP Top 10 - A09) Security Logging and Monitoring Failure

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
DotcmsDotcms22.02 (including)22.03.15 (excluding)
DotcmsDotcms23.01 (including)23.01.15 (excluding)
DotcmsDotcms23.02 (including)23.09.7 (including)
DotcmsDotcms23.10.24-1 (including)23.10.24-1 (including)
DotcmsDotcms23.10.24-2 (including)23.10.24-2 (including)
DotcmsDotcms23.10.24-3 (including)23.10.24-3 (including)
DotcmsDotcms23.10.24-4 (including)23.10.24-4 (including)
DotcmsDotcms23.10.24-5 (including)23.10.24-5 (including)
DotcmsDotcms23.10.24-6 (including)23.10.24-6 (including)
DotcmsDotcms23.10.24-7 (including)23.10.24-7 (including)

Potential Mitigations

References