CVE-2023-31056

CloverDX before 5.17.3 writes passwords to the audit log in certain situations, if the audit log is enabled and single sign-on is not employed. The fixed versions are 5.15.4, 5.16.2, 5.17.3, and 6.0.x.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cloverdx:cloverdx:*:*:*:*:*:*:*:*
cpe:2.3:a:cloverdx:cloverdx:*:*:*:*:*:*:*:*
cpe:2.3:a:cloverdx:cloverdx:*:*:*:*:*:*:*:*
cpe:2.3:a:cloverdx:cloverdx:5.16.0:*:*:*:*:*:*:*
cpe:2.3:a:cloverdx:cloverdx:5.16.1:*:*:*:*:*:*:*

History

29 Apr 2023, 03:06

Type Values Removed Values Added
CWE CWE-532
CPE cpe:2.3:a:cloverdx:cloverdx:*:*:*:*:*:*:*:*
cpe:2.3:a:cloverdx:cloverdx:5.16.0:*:*:*:*:*:*:*
cpe:2.3:a:cloverdx:cloverdx:5.16.1:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
First Time Cloverdx
Cloverdx cloverdx
References (MISC) https://support1.cloverdx.com/hc/en-us/articles/8484869595164-Security-advisory-April-2023 - (MISC) https://support1.cloverdx.com/hc/en-us/articles/8484869595164-Security-advisory-April-2023 - Mitigation, Vendor Advisory

24 Apr 2023, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-24 03:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-31056

Mitre link : CVE-2023-31056

CVE.ORG link : CVE-2023-31056


JSON object : View

Products Affected

cloverdx

  • cloverdx
CWE
CWE-532

Insertion of Sensitive Information into Log File