CVE-2020-25640

MEDIUM

WildFly < 21.0.0 - Sensitive Information Disclosure in Resource Adapter Logs

Title source: llm
STIX 2.1

Description

A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in the log file.

References (3)

Core 3
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1881637
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20201210-0001/

Scores

CVSS v3 5.3
EPSS 0.0133
EPSS Percentile 67.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-209 CWE-532
Status published
Products (2)
org.wildfly/wildfly-parent 0 - 21.0.0.FinalMaven
redhat/wildfly < 21.0.0
Published Nov 24, 2020
Tracked Since Feb 18, 2026