CVE-2020-25640
published 2020-11-24CVE-2020-25640: A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting…
PriorityP427medium5.3CVSS 3.1
AVNACHPRLUINSUCHINAN
EPSS
1.33%
67.9th percentile
A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in the log file.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | wildfly | < 21.0.0 | 21.0.0 |
| redhat | wildfly | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:P/I:N/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Wildfly logs plaintext passwords
osv·2022-02-15
CVE-2020-25640 [MEDIUM] Wildfly logs plaintext passwords
Wildfly logs plaintext passwords
A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in the log file.
GHSA
Wildfly logs plaintext passwords
ghsa·2022-02-15
CVE-2020-25640 [MEDIUM] CWE-209 Wildfly logs plaintext passwords
Wildfly logs plaintext passwords
A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in the log file.
Red Hat
wildfly: resource adapter logs plaintext JMS password at warning level on connection error
vendor_redhat·2020-09-10·CVSS 5.3
CVE-2020-25640 [MEDIUM] CWE-209 wildfly: resource adapter logs plaintext JMS password at warning level on connection error
wildfly: resource adapter logs plaintext JMS password at warning level on connection error
A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in the log file.
A flaw was found in wildfly. JMS passwords are logged by the resource adaptor in plain text at the warning level when a connection error occurs allowing any user that has access to the log to gain access to this sensitive information. The highest threat from this vulnerability is to data confidentiality.
Package: wildfly (Red Hat Data Grid 8) - Not affected
Package: wildfly (Red Hat Decision Manager 7) - Not affected
Package: wildfly (Red Hat JBoss Data Grid 7) - Out of support scope
Package: jbossas (Red
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-25640 wildfly: resource adapter logs plaintext JMS password at warning level on connection error [fedora-all]
bugzilla·2020-09-24·CVSS 5.3
CVE-2020-25640 [MEDIUM] CVE-2020-25640 wildfly: resource adapter logs plaintext JMS password at warning level on connection error [fedora-all]
CVE-2020-25640 wildfly: resource adapter logs plaintext JMS password at warning level on connection error [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2020-25640 wildfly: resource adapter logs plaintext JMS password at warning level on connection error
bugzilla·2020-09-22·CVSS 5.3
CVE-2020-25640 [MEDIUM] CVE-2020-25640 wildfly: resource adapter logs plaintext JMS password at warning level on connection error
CVE-2020-25640 wildfly: resource adapter logs plaintext JMS password at warning level on connection error
A flaw was found in WildFly. Resource adapter logs plain text JMS password at warning level on connection error.
Discussion:
External References:
https://github.com/amqphub/amqp-10-resource-adapter/issues/13
---
Created wildfly tracking bugs for this issue:
Affects: fedora-all [bug 1882385]
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform
Via RHSA-2021:0250 https://access.redhat.com/errata/RHSA-2021:0250
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6
Via RHSA-2021:0246 https://access.redhat.com/errata/RHSA-2021:0246
---
This issue has bee
https://bugzilla.redhat.com/show_bug.cgi?id=1881637https://github.com/amqphub/amqp-10-resource-adapter/issues/13https://security.netapp.com/advisory/ntap-20201210-0001/https://bugzilla.redhat.com/show_bug.cgi?id=1881637https://github.com/amqphub/amqp-10-resource-adapter/issues/13https://security.netapp.com/advisory/ntap-20201210-0001/
2020-11-24
Published