CVE-2019-3888
—CVSS 3.1
9.8 critical
EPSS
3%p87
Published
()
Modified
Description
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)
In the news0 stories
No ingested article mentions this CVE yet.