CVE-2023-23591
Summary
| CVE | CVE-2023-23591 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-12 14:15:00 UTC |
| Updated | 2023-04-19 19:34:00 UTC |
| Description | The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs when debug logging is enabled. The fixed versions are 8.2.18.7, 8.2.18.2.2, 8.3.11.1, and 8.3.14.1. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Terminalfour | Terminalfour | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release Notes Highlights - Terminalfour Knowledge Base | MISC | docs.terminalfour.com | Release Notes |
| Terminalfour 8.3.15 Release Notes - Terminalfour Knowledge Base | MISC | docs.terminalfour.com | Release Notes |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.