漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Io.quarkiverse.cxf:quarkus-cxf: quarkus cxf may log user password and secret to application log
Vulnerability Description
A vulnerability was found in Quarkus CXF. Passwords and other secrets may appear in the application log in spite of the user configuring them to be hidden. This issue requires some special configuration to be vulnerable, such as SOAP logging enabled, application set client, and endpoint logging properties, and the attacker must have access to the application log.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
通过日志文件的信息暴露
Vulnerability Title
Quarkus CXF 日志信息泄露漏洞
Vulnerability Description
Quarkus CXF是Quarkiverse开源的一个扩展。 Quarkus CXF存在日志信息泄露漏洞,该漏洞源于尽管用户将密码和其他机密配置为隐藏,但它们可能会出现在应用程序日志中。
CVSS Information
N/A
Vulnerability Type
N/A