CVE-2019-10212
published 2019-10-02CVE-2019-10212: A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the…
PriorityP349critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.90%
77.3th percentile
A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 2.0.27-1 (forky) | undertow 2.0.27-1 (forky) |
| redhat | jboss_data_grid | 7.0.0 – 7.3 | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_fuse | 7.0.0 – 7.4 | — |
| redhat | single_sign-on | 7.0 – 7.3 | — |
| redhat | undertow | < 2.0.20 | 2.0.20 |
| redhat | undertow | — | — |
| redhat | undertow | >= 0 < 2.0.27-1 | 2.0.27-1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv3.04.8MEDIUMCVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Potential to access user credentials from the log files when debug logging enabled
ghsa·2019-11-20
CVE-2019-10212 [CRITICAL] CWE-532 Potential to access user credentials from the log files when debug logging enabled
Potential to access user credentials from the log files when debug logging enabled
A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.
OSV
Potential to access user credentials from the log files when debug logging enabled
osv·2019-11-20
CVE-2019-10212 [CRITICAL] Potential to access user credentials from the log files when debug logging enabled
Potential to access user credentials from the log files when debug logging enabled
A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.
OSV
CVE-2019-10212: A flaw was found in, all under 2
osv·2019-10-02·CVSS 9.8
CVE-2019-10212 [CRITICAL] CVE-2019-10212: A flaw was found in, all under 2
A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.
Red Hat
undertow: DEBUG log for io.undertow.request.security if enabled leaks credentials to log files
vendor_redhat·2019-09-30·CVSS 9.8
CVE-2019-10212 [CRITICAL] CWE-532 undertow: DEBUG log for io.undertow.request.security if enabled leaks credentials to log files
undertow: DEBUG log for io.undertow.request.security if enabled leaks credentials to log files
A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.
A flaw was found in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user’s credentials from the log files.
Statement: All the Red Hat products using the undertow-core jar version 2.0.20 or before are affected.
Mitigation: Use Elytron instead of legacy Security subsystem.
Package: undertow (Red Hat Fuse 7) - Will not fix
Package: jbossweb (Red Hat JBoss Enterprise Application Platform 6) - Out of support scope
Package: undertow
Debian
CVE-2019-10212: undertow - A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow...
vendor_debian·2019·CVSS 9.8
CVE-2019-10212 [CRITICAL] CVE-2019-10212: undertow - A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow...
A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.
Scope: local
forky: resolved (fixed in 2.0.27-1)
sid: resolved (fixed in 2.0.27-1)
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2019:2998https://access.redhat.com/errata/RHSA-2020:0727https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10212https://security.netapp.com/advisory/ntap-20220210-0017/https://access.redhat.com/errata/RHSA-2019:2998https://access.redhat.com/errata/RHSA-2020:0727https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10212https://security.netapp.com/advisory/ntap-20220210-0017/
2019-10-02
Published