CVE-2024-8097 MEDIUM

CVE-2024-8097: Sensitive information exposure when the org.glassfish.admingui LOGGER is set to FINEST level

Vendor Payara Platform
Product Payara Server
Weakness CWE-200 · Info exposure
Published September 11, 2024
Last update September 11, 2024

CVSS base score

6.7/10
Attack vector Local
Attack complexity Low
Privileges required High
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N

What the vulnerability does

01Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Payara Platform Payara Server (Logging modules) allows Sensitive credentials posted in plain-text on the server log.This issue affects Payara Server: from 6.0.0 before 6.18.0, from 6.2022.1 before 6.2024.9, from 5.20.0 before 5.67.0, from 5.2020.2 before 5.2022.5, from 4.1.2.191.0 before 4.1.2.191.50.

Key dates

02Disclosure timeline

September 11, 2024 CVE published
September 11, 2024 Record updated