CVE Vulnerabilities

CVE-2025-6391

Insertion of Sensitive Information into Log File

Published: Jul 17, 2025 | Modified: Jul 22, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withdraw the unencrypted tokens with security implications, such as unauthorized access, session hijacking, and information disclosure.

Weakness

The product writes sensitive information to a log file.

Potential Mitigations

References