System->Maintenance-> Log Files in dotCMS dashboard is...
Moderate severity
Unreviewed
Published
Apr 2, 2024
to the GitHub Advisory Database
•
Updated Sep 30, 2024
Description
Published by the National Vulnerability Database
Apr 1, 2024
Published to the GitHub Advisory Database
Apr 2, 2024
Last updated
Sep 30, 2024
System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it requires a backend admin as well as that dbs are locked down by environment.
OWASP Top 10 - A05) Insecure Design
OWASP Top 10 - A05) Security Misconfiguration
OWASP Top 10 - A09) Security Logging and Monitoring Failure
References