CVE-2024-3165
01.04.2024, 22:15
System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it requires a backend admin as well as that dbs are locked down by environment. OWASP Top 10 - A05) Insecure Design OWASP Top 10 - A05) Security Misconfiguration OWASP Top 10 - A09) Security Logging and Monitoring FailureEnginsight
Vendor | Product | Version |
---|---|---|
dotcms | dotcms | 22.02 ≤ 𝑥 < 22.03.15 |
dotcms | dotcms | 23.01 ≤ 𝑥 < 23.01.15 |
dotcms | dotcms | 23.02 ≤ 𝑥 ≤ 23.09.7 |
dotcms | dotcms | 23.10.24:1 |
dotcms | dotcms | 23.10.24:2 |
dotcms | dotcms | 23.10.24:3 |
dotcms | dotcms | 23.10.24:4 |
dotcms | dotcms | 23.10.24:5 |
dotcms | dotcms | 23.10.24:6 |
dotcms | dotcms | 23.10.24:7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration