CVE-2019-10212
Summary
| CVE | CVE-2019-10212 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-02 19:15:00 UTC |
| Updated | 2022-02-20 06:20:00 UTC |
| Description | A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| CVE-2019-10212 Undertow Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| 1731984 – (CVE-2019-10212) CVE-2019-10212 undertow: DEBUG log for io.undertow.request.security if enabled leaks credentials to log files |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking, Mitigation, Vendor Advisory |
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| Red Hat Customer Portal |
REDHAT |
access.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981625 Java (maven) Security Update for io.undertow:undertow-core (GHSA-8vh8-vc28-m2hf)