CVE Vulnerabilities

CVE-2025-6391

Insertion of Sensitive Information into Log File

Published: Jul 17, 2025 | Modified: Feb 02, 2026
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withdraw the unencrypted tokens with security implications, such as unauthorized access, session hijacking, and information disclosure.

Weakness

The product writes sensitive information to a log file.

Affected Software

NameVendorStart VersionEnd Version
AscgBrocade*3.3.0 (excluding)

Potential Mitigations

References