Description
A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in the log file.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1881637
https://github.com/amqphub/amqp-10-resource-adapter/issues/13
https://security.netapp.com/advisory/ntap-20201210-0001/
Related Vulnerabilities
CVE-2021-28168 Vulnerability in maven package org.glassfish.jersey.core:jersey-common
CVE-2023-36469 Vulnerability in maven package org.xwiki.platform:xwiki-platform-notifications-ui
CVE-2016-10735 Vulnerability in maven package org.wildfly.swarm:bootstrap
CVE-2021-25978 Vulnerability in npm package apostrophe
CVE-2022-23615 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore