A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HNetapp Active Iq Unified Manager
APPNetappall versionsRed Hat Enterprise Linux
OSRedhat6.07.08.0Red Hat Jboss Data Grid
APPRedhat7.0.0 – 7.3Red Hat Jboss Enterprise Application Platform
APPRedhat7.27.37.4Red Hat Jboss Fuse
APPRedhat7.0.0 – 7.4Red Hat Openshift Application Runtimes
APPRedhatall versionsRed Hat Single Sign On
APPRedhat7.0 – 7.3Red Hat Undertow
APPRedhat< 2.0.20
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
References
Related vulnerabilities
CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓same product
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
CVE-2021-44228CRITICAL10.0⚠ KEVPL ✓same product
Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup
CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
CVE-2018-14667CRITICAL9.8⚠ KEVPL ✓same product
RCE przez EL injection w RichFaces Framework 3.X — brak uwierzytelnienia
CVE-2017-12149CRITICAL9.8⚠ KEVPL ✓same product
RCE przez niebezpieczną deserializację w JBoss HTTP Invoker (EAP 5.2)