CVE-2024-9621
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Oct 8, 2024
Updated: Dec 6, 2024
CWE ID 532
Summary
CVE-2024-9621 is a vulnerability affecting Quarkus CXF. Under certain configurations, such as SOAP logging enabled and endpoint logging properties set, passwords and other secrets may inadvertently be logged and exposed in the application. For this vulnerability to be exploited, an attacker must have access to the application log. It is important to note that not all Quarkus CXF deployments are affected, and the vulnerability requires specific configurations to be present.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.