CVE-2024-1102
MEDIUMDescription
A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for the database-connection.
Is your site exposed to CVE-2024-1102?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| jberet | jberet |
| redhat | jboss_enterprise_application_platform |
| redhat | jboss_enterprise_application_platform |
References
Other References
Frequently Asked Questions
What is CVE-2024-1102? +
How severe is CVE-2024-1102? +
What products are affected by CVE-2024-1102? +
How do I check if I'm vulnerable to CVE-2024-1102? +
Related Vulnerabilities
Unprotected Transport of Credentials vulnerability in OpenText™ Documentum™ Server could allow Credential Stuffing.This issue affects Documentum™ Server: from 16.7 through …
Brocade ASCG before 3.2.0 Web Interface is not enforcing HSTS, as defined by RFC 6797. HSTS is an optional response …
Audiobookshelf is an open-source self-hosted audiobook server. In versions 2.6.0 through 2.26.3, the application does not properly restrict redirect callback …
Brightpick Mission Control discloses device telemetry, configuration, and credential information via WebSocket traffic to unauthenticated users when they connect to …
Open OnDemand provides remote web access to supercomputers. In versions 4.0.8 and prior, the Apache proxy allows sensitive headers to …
The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle.