First published: Tue Jan 18 2022(Updated: )
In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log wrote sensitive information to log. Mitigating factors are logging is disabled by default.
Credit: security@m-files.com
Affected Software | Affected Version | How to fix |
---|---|---|
M-files M-files Server | <21.11.10775.0 |
Upgrade to M-Files version 21.11.10775.0 or newer.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-41808 is a vulnerability in the M-Files Server product that allows sensitive information to be logged when enabling Federated authentication logging to the event log.
Versions of M-Files Server prior to 21.11.10775.0 are affected by CVE-2021-41808.
No, logging of Federated authentication is disabled by default.
The severity of CVE-2021-41808 is rated as low (2.3).
To mitigate the vulnerability, ensure that logging of Federated authentication is disabled.