CVE-2024-3165
Severity CVSS v4.0:
Pending analysis
Type:
CWE-532
Information Exposure Through Log Files
Publication date:
01/04/2024
Last modified:
27/06/2025
Description
System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it requires a backend admin as well as that dbs are locked down by environment. <br />
<br />
OWASP Top 10 - A05) Insecure Design<br />
<br />
OWASP Top 10 - A05) Security Misconfiguration<br />
<br />
OWASP Top 10 - A09) Security Logging and Monitoring Failure
Impact
Base Score 3.x
4.50
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:dotcms:dotcms:*:*:*:*:*:*:*:* | 22.02 (including) | 22.03.15 (excluding) |
cpe:2.3:a:dotcms:dotcms:*:*:*:*:*:*:*:* | 23.01 (including) | 23.01.15 (excluding) |
cpe:2.3:a:dotcms:dotcms:*:*:*:*:*:*:*:* | 23.02 (including) | 23.09.7 (including) |
cpe:2.3:a:dotcms:dotcms:23.10.24:1:*:*:lts:*:*:* | ||
cpe:2.3:a:dotcms:dotcms:23.10.24:2:*:*:lts:*:*:* | ||
cpe:2.3:a:dotcms:dotcms:23.10.24:3:*:*:lts:*:*:* | ||
cpe:2.3:a:dotcms:dotcms:23.10.24:4:*:*:lts:*:*:* | ||
cpe:2.3:a:dotcms:dotcms:23.10.24:5:*:*:lts:*:*:* | ||
cpe:2.3:a:dotcms:dotcms:23.10.24:6:*:*:lts:*:*:* | ||
cpe:2.3:a:dotcms:dotcms:23.10.24:7:*:*:lts:*:*:* |
To consult the complete list of CPE names with products and versions, see this page