Medium severity4.5NVD Advisory· Published Apr 1, 2024· Updated Jun 17, 2026
CVE-2024-3165
CVE-2024-3165
Description
System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it requires a backend admin as well as that dbs are locked down by environment.
OWASP Top 10 - A05) Insecure Design
OWASP Top 10 - A05) Security Misconfiguration
OWASP Top 10 - A09) Security Logging and Monitoring Failure
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10(expand)+ 9 more
- (no CPE)
- (no CPE)range: 22.02 and after
- cpe:2.3:a:dotcms:dotcms:*:*:*:*:*:*:*:*range: >=22.02,<22.03.15
- cpe:2.3:a:dotcms:dotcms:23.10.24:1:*:*:lts:*:*:*
- cpe:2.3:a:dotcms:dotcms:23.10.24:2:*:*:lts:*:*:*
- cpe:2.3:a:dotcms:dotcms:23.10.24:3:*:*:lts:*:*:*
- cpe:2.3:a:dotcms:dotcms:23.10.24:4:*:*:lts:*:*:*
- cpe:2.3:a:dotcms:dotcms:23.10.24:5:*:*:lts:*:*:*
- cpe:2.3:a:dotcms:dotcms:23.10.24:6:*:*:lts:*:*:*
- cpe:2.3:a:dotcms:dotcms:23.10.24:7:*:*:lts:*:*:*
Patches
Vulnerability mechanics
References
3- github.com/dotCMS/core/issues/27910nvdIssue Tracking
- github.com/dotCMS/core/pull/28006nvdIssue Tracking
- www.dotcms.com/security/SI-70nvdBroken Link
News mentions
0No linked articles in our index yet.