First published: Thu Feb 23 2023(Updated: )
Potential Insertion of Sensitive Information into Jetty Log Files in multiple versions of OpenNMS Meridian and Horizon could allow disclosure of usernames and passwords if the logging level is set to debug. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet.
Credit: security@opennms.com
Affected Software | Affected Version | How to fix |
---|---|---|
OpenNMS Horizon | <31.0.4 | |
OpenNMS Meridian | <2023.1.0 |
<logger name="org.eclipse.jetty.server.HttpInput" additivity="false" level="INFO"> 2 <appender-ref ref="RoutingAppender"/> 3 </logger> https://github.com/OpenNMS/opennms/pull/5741 https://github.com/OpenNMS/opennms/pull/5741 or upgrade to a newer version of Meridian or Horizon.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-0815.
The severity of CVE-2023-0815 is medium with a severity value of 6.5.
The impact of CVE-2023-0815 is the potential disclosure of usernames and passwords if the logging level is set to debug.
To fix CVE-2023-0815, users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4.
You can find more information about CVE-2023-0815 in the OpenNMS Meridian and Horizon release notes and the associated GitHub pull request.