CVE-2023-31056

CloverDX before 5.17.3 writes passwords to the audit log in certain situations, if the audit log is enabled and single sign-on is not employed. The fixed versions are 5.15.4, 5.16.2, 5.17.3, and 6.0.x.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cloverdx:cloverdx:*:*:*:*:*:*:*:*
cpe:2.3:a:cloverdx:cloverdx:*:*:*:*:*:*:*:*
cpe:2.3:a:cloverdx:cloverdx:*:*:*:*:*:*:*:*
cpe:2.3:a:cloverdx:cloverdx:5.16.0:*:*:*:*:*:*:*
cpe:2.3:a:cloverdx:cloverdx:5.16.1:*:*:*:*:*:*:*

History

21 Nov 2024, 08:01

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 9.1
References () https://support1.cloverdx.com/hc/en-us/articles/8484869595164-Security-advisory-April-2023 - Mitigation, Vendor Advisory () https://support1.cloverdx.com/hc/en-us/articles/8484869595164-Security-advisory-April-2023 - Mitigation, Vendor Advisory

Information

Published : 2023-04-24 03:15

Updated : 2024-11-21 08:01


NVD link : CVE-2023-31056

Mitre link : CVE-2023-31056

CVE.ORG link : CVE-2023-31056


JSON object : View

Products Affected

cloverdx

  • cloverdx
CWE
CWE-532

Insertion of Sensitive Information into Log File