CVE-2023-0815: Plaintext Password Present in the Web logs
Potential Insertion of Sensitive Information into Jetty Log Files in multiple versions of OpenNMS Meridian and Horizon could allow disclosure of usernames and passwords if the logging level is set to debug. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-0815.
What is the severity of CVE-2023-0815?
The severity of CVE-2023-0815 is medium with a severity value of 6.5.
What is the impact of CVE-2023-0815?
The impact of CVE-2023-0815 is the potential disclosure of usernames and passwords if the logging level is set to debug.
How can I fix CVE-2023-0815?
To fix CVE-2023-0815, users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4.
Where can I find more information about CVE-2023-0815?
You can find more information about CVE-2023-0815 in the OpenNMS Meridian and Horizon release notes and the associated GitHub pull request.