CVE-2019-3888 PUBLISHED

A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)

EPSS 0.59% · 69.0th percentile

Risk Scores

EPSS Score
0.59%
69.0th percentile

Affected Products

VendorProductVersions
Ubuntu:25.10undertow0, 2.3.18-2, 2.3.18-1
Ubuntu:18.04:LTSundertow1.4.22-1, 0, 1.4.20-1
Ubuntu:24.04:LTSundertow2.3.8-2, 0
Ubuntu:16.04:LTSundertow1.3.4-1, 1.3.11-1, 1.3.16-1
Ubuntu:20.04:LTSundertow0

Timeline

References

Open in Interactive Console →