CVE-2020-25640

MEDIUM

Redhat Wildfly < 21.0.0 - Error Information Exposure

Title source: rule
STIX 2.1

Description

A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inserting sensitive information in the log file.

References (3)

Core 3
Core References
Issue Tracking, Vendor Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1881637
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20201210-0001/

Scores

CVSS v3 5.3
EPSS 0.0035
EPSS Percentile 57.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-532 CWE-209
Status published
Products (2)
org.wildfly/wildfly-parent 0 - 21.0.0.FinalMaven
redhat/wildfly < 21.0.0
Published Nov 24, 2020
Tracked Since Feb 18, 2026