CVE-2023-23591

The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs when debug logging is enabled. The fixed versions are 8.2.18.7, 8.2.18.2.2, 8.3.11.1, and 8.3.14.1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:terminalfour:terminalfour:*:*:*:*:*:*:*:*
cpe:2.3:a:terminalfour:terminalfour:*:*:*:*:*:*:*:*
cpe:2.3:a:terminalfour:terminalfour:*:*:*:*:*:*:*:*
cpe:2.3:a:terminalfour:terminalfour:*:*:*:*:*:*:*:*

History

10 Feb 2025, 16:15

Type Values Removed Values Added
CWE CWE-532

Information

Published : 2023-04-12 14:15

Updated : 2025-02-10 16:15


NVD link : CVE-2023-23591

Mitre link : CVE-2023-23591

CVE.ORG link : CVE-2023-23591


JSON object : View

Products Affected

terminalfour

  • terminalfour
CWE
NVD-CWE-noinfo CWE-532

Insertion of Sensitive Information into Log File