CVE-2024-9621

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Oct 8, 2024
Updated: Dec 6, 2024
CWE ID 532

Summary

CVE-2024-9621 is a vulnerability affecting Quarkus CXF. Under certain configurations, such as SOAP logging enabled and endpoint logging properties set, passwords and other secrets may inadvertently be logged and exposed in the application. For this vulnerability to be exploited, an attacker must have access to the application log. It is important to note that not all Quarkus CXF deployments are affected, and the vulnerability requires specific configurations to be present.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share