Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. io.quarkiverse.cxf/quarkus-cxf
  4. ›
  5. CVE-2024-9621

CVE-2024-9621: Quarkus CXF logs passwords and other secrets

October 8, 2024 (updated December 6, 2024)

A vulnerability was found in Quarkus CXF. Passwords and other secrets may appear in the application log in spite of the user configuring them to be hidden. This issue requires some special configuration to be vulnerable, such as SOAP logging enabled, application set client, and endpoint logging properties, and the attacker must have access to the application log.

References

  • access.redhat.com/errata/RHSA-2024:10035
  • access.redhat.com/security/cve/CVE-2024-9621
  • bugzilla.redhat.com/show_bug.cgi?id=2317130
  • docs.quarkiverse.io/quarkus-cxf/dev/release-notes/3.15.2.html
  • github.com/advisories/GHSA-jqh2-ch7p-xwxh
  • github.com/quarkiverse/quarkus-cxf
  • github.com/quarkiverse/quarkus-cxf/commit/8ed72cab8db8e5659e294b05529d2b45557859bd
  • github.com/quarkiverse/quarkus-cxf/issues/1533
  • nvd.nist.gov/vuln/detail/CVE-2024-9621

Code Behaviors & Features

Detect and mitigate CVE-2024-9621 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 3.15.2

Fixed versions

  • 3.15.2

Solution

Upgrade to version 3.15.2 or above.

Impact 5.3 MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-532: Insertion of Sensitive Information into Log File

Source file

maven/io.quarkiverse.cxf/quarkus-cxf/CVE-2024-9621.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:41 +0000.