QID 982713

QID 982713: Java (maven) Security Update for io.undertow:undertow-core (GHSA-jwgx-9mmh-684w)

A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to refer to GHSA-jwgx-9mmh-684w for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 982713

    Software Advisories
    Advisory ID Software Component Link
    GHSA-jwgx-9mmh-684w io.undertow:undertow-core URL Logo github.com/advisories/GHSA-jwgx-9mmh-684w