Description
A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.
Remediation
References
https://access.redhat.com/errata/RHSA-2019:2998
https://access.redhat.com/errata/RHSA-2020:0727
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10212
https://security.netapp.com/advisory/ntap-20220210-0017/
Related Vulnerabilities
CVE-2022-2216 Vulnerability in maven package org.webjars.npm:parse-url
CVE-2020-13957 Vulnerability in maven package org.apache.solr:solr-core
CVE-2022-25873 Vulnerability in maven package org.webjars.npm:vuetify
CVE-2023-2585 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2019-8331 Vulnerability in maven package org.webjars.bowergithub.angular-ui:bootstrap