Unrated severityNVD Advisory· Published Jan 8, 2020· Updated Sep 16, 2024
Pivotal Ops Manager logs query parameters in tomcat access file
CVE-2019-11292
Description
Pivotal Ops Manager, versions 2.4.x prior to 2.4.27, 2.5.x prior to 2.5.24, 2.6.x prior to 2.6.16, and 2.7.x prior to 2.7.5, logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, ie. credentials, then they will be logged as well.
Affected products
1- Range: 2.7
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- pivotal.io/security/cve-2019-11292mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.