CVE-2024-1102
published 2024-04-25CVE-2024-1102: A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for the…
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.79%
52.1th percentile
A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for the database-connection.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jberet | jberet | < 2.2.1 | 2.2.1 |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Jberet: jberet-core logging database credentials
osv·2024-04-25
CVE-2024-1102 [MEDIUM] Jberet: jberet-core logging database credentials
Jberet: jberet-core logging database credentials
A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for the database-connection.
GHSA
Jberet: jberet-core logging database credentials
ghsa·2024-04-25
CVE-2024-1102 [MEDIUM] CWE-200 Jberet: jberet-core logging database credentials
Jberet: jberet-core logging database credentials
A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for the database-connection.
Red Hat
jberet: jberet-core logging database credentials
vendor_redhat·2024-01-29·CVSS 6.5
CVE-2024-1102 [MEDIUM] CWE-523 jberet: jberet-core logging database credentials
jberet: jberet-core logging database credentials
A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for the database-connection.
A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for the database-connection.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: jberet-core (Red Hat Build of Keycloak) - Not affected
Package: jberet-core (Red Hat Data Grid 8) - Not affected
Package: jberet-core (Red Ha
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2024:1677https://access.redhat.com/errata/RHSA-2024:3580https://access.redhat.com/errata/RHSA-2024:3581https://access.redhat.com/errata/RHSA-2024:3583https://access.redhat.com/security/cve/CVE-2024-1102https://bugzilla.redhat.com/show_bug.cgi?id=2262060https://github.com/jberet/jsr352/issues/452https://access.redhat.com/errata/RHSA-2024:3580https://access.redhat.com/errata/RHSA-2024:3581https://access.redhat.com/errata/RHSA-2024:3583https://access.redhat.com/security/cve/CVE-2024-1102https://bugzilla.redhat.com/show_bug.cgi?id=2262060https://github.com/jberet/jsr352/issues/452
2024-04-25
Published