VulnerabilityModified
CVE-2020-25640
A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in the log file.
MEDIUM 5.3EPSS 1.35%
Does this matter?
Lower severity and a low EPSS score (1.35%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in the log file.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.35% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-209, CWE-532
- Affected
- redhat/wildfly
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1881637Issue Tracking, Vendor Advisory
- https://github.com/amqphub/amqp-10-resource-adapter/issues/13Third Party Advisory
- https://security.netapp.com/advisory/ntap-20201210-0001/Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1881637Issue Tracking, Vendor Advisory
- https://github.com/amqphub/amqp-10-resource-adapter/issues/13Third Party Advisory
- https://security.netapp.com/advisory/ntap-20201210-0001/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.