Wildfly logs plaintext passwords
Moderate severity
GitHub Reviewed
Published
Feb 15, 2022
to the GitHub Advisory Database
•
Updated Jul 13, 2023
Package
Affected versions
< 21.0.0.Final
Patched versions
21.0.0.Final
Description
Published by the National Vulnerability Database
Nov 24, 2020
Published to the GitHub Advisory Database
Feb 15, 2022
Reviewed
Jul 13, 2023
Last updated
Jul 13, 2023
A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in the log file.
References