Show filters
1 Total Results
Displaying 1-1 of 1
Sort by:
Attacker Value
Unknown

UAA logs all query parameters with debug logging level

Disclosure Date: December 06, 2019 (last updated November 27, 2024)
Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter. A remote authenticated malicious user could gain access to user credentials via the uaa.log file if authentication is provided via query parameters.