VYPR
Medium severity4.5NVD Advisory· Published Apr 1, 2024· Updated Jun 17, 2026

CVE-2024-3165

CVE-2024-3165

Description

System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it requires a backend admin as well as that dbs are locked down by environment.

OWASP Top 10 - A05) Insecure Design

OWASP Top 10 - A05) Security Misconfiguration

OWASP Top 10 - A09) Security Logging and Monitoring Failure

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

10
  • Dotcms/Dotcmsllm-fuzzy10 versions
    (expand)+ 9 more
    • (no CPE)
    • (no CPE)range: 22.02 and after
    • cpe:2.3:a:dotcms:dotcms:*:*:*:*:*:*:*:*range: >=22.02,<22.03.15
    • cpe:2.3:a:dotcms:dotcms:23.10.24:1:*:*:lts:*:*:*
    • cpe:2.3:a:dotcms:dotcms:23.10.24:2:*:*:lts:*:*:*
    • cpe:2.3:a:dotcms:dotcms:23.10.24:3:*:*:lts:*:*:*
    • cpe:2.3:a:dotcms:dotcms:23.10.24:4:*:*:lts:*:*:*
    • cpe:2.3:a:dotcms:dotcms:23.10.24:5:*:*:lts:*:*:*
    • cpe:2.3:a:dotcms:dotcms:23.10.24:6:*:*:lts:*:*:*
    • cpe:2.3:a:dotcms:dotcms:23.10.24:7:*:*:lts:*:*:*

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.