Description
A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Easy Slideshow Multiple Cross-Site Request Forgery Vulnerabilities (1.0.3)
ownCloud Other Vulnerability (CVE-2014-2056)
Grafana Improper Authentication Vulnerability (CVE-2022-32276)
MySQL CVE-2022-21303 Vulnerability (CVE-2022-21303)
Liferay Portal Incorrect Authorization Vulnerability (CVE-2024-38002)