Loading HuntDB...

GHSA-8vh8-vc28-m2hf

GitHub Security Advisory

Potential to access user credentials from the log files when debug logging enabled

✓ GitHub Reviewed CRITICAL Has CVE

Advisory Details

A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.

Affected Packages

Maven io.undertow:undertow-core
Affected versions: 0 (fixed in 2.0.20)

Related CVEs

Key Information

GHSA ID
GHSA-8vh8-vc28-m2hf
Published
November 20, 2019 1:33 AM
Last Modified
February 11, 2022 9:12 PM
CVSS Score
9.0 /10
Primary Ecosystem
Maven
Primary Package
io.undertow:undertow-core
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 18, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.