First published: Fri Dec 30 2022(Updated: )
Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specific configurations were set.
Credit: security@m-files.com security@m-files.com
Affected Software | Affected Version | How to fix |
---|---|---|
M-files M-files Server | <22.10.11846.0 | |
<22.10.11846.0 |
Upgrade to non-vulnerable version of M-Files.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4858 is a vulnerability in M-Files Server before version 22.10.11846.0 that allows the insertion of sensitive information into log files.
CVE-2022-4858 can be exploited by an attacker to obtain sensitive tokens from the log files if specific configurations are set.
CVE-2022-4858 has a severity rating of 7.5 (High).
To fix CVE-2022-4858, users should update their M-Files Server to version 22.10.11846.0 or later.
You can find more information about CVE-2022-4858 at the following link: https://www.m-files.com/about/trust-center/security-advisories/cve-2022-4858/