CVE-2023-23591

The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs when debug logging is enabled. The fixed versions are 8.2.18.7, 8.2.18.2.2, 8.3.11.1, and 8.3.14.1.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:terminalfour:terminalfour:*:*:*:*:*:*:*:*
cpe:2.3:a:terminalfour:terminalfour:*:*:*:*:*:*:*:*
cpe:2.3:a:terminalfour:terminalfour:*:*:*:*:*:*:*:*
cpe:2.3:a:terminalfour:terminalfour:*:*:*:*:*:*:*:*

History

10 Feb 2025, 16:15

Type Values Removed Values Added
CWE CWE-532

21 Nov 2024, 07:46

Type Values Removed Values Added
References () https://docs.terminalfour.com/articles/release-notes-highlights/ - Release Notes () https://docs.terminalfour.com/articles/release-notes-highlights/ - Release Notes
References () https://docs.terminalfour.com/release-notes/83/15.html - Release Notes () https://docs.terminalfour.com/release-notes/83/15.html - Release Notes

19 Apr 2023, 19:34

Type Values Removed Values Added
New CVE

Information

Published : 2023-04-12 14:15

Updated : 2025-02-10 16:15


NVD link : CVE-2023-23591

Mitre link : CVE-2023-23591

CVE.ORG link : CVE-2023-23591


JSON object : View

Products Affected

terminalfour

  • terminalfour
CWE
NVD-CWE-noinfo CWE-532

Insertion of Sensitive Information into Log File