Description
A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.
Remediation
References
Related Vulnerabilities
IBM WebSEAL Missing Authorization Vulnerability (CVE-2019-4158)
ReviveAdserver Other Vulnerability (CVE-2016-9471)
MySQL CVE-2017-10227 Vulnerability (CVE-2017-10227)
MySQL CVE-2013-1570 Vulnerability (CVE-2013-1570)
XWiki URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2023-29204)