First published: Wed Feb 05 2025(Updated: )
When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager may log sensitive information in the pgaudit log files.
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP Next Central Manager | >=20.2.0<=20.2.1 | 20.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of F5-K000149185 is classified as medium due to the potential exposure of sensitive user information.
To fix F5-K000149185, you should upgrade to a version of BIG-IP Next Central Manager that is beyond 20.3.0.
F5-K000149185 may log sensitive authentication data, including usernames and passwords, in pgaudit log files.
F5-K000149185 affects users of F5 BIG-IP Next Central Manager operating between versions 20.2.0 and 20.3.0.
F5-K000149185 was identified and disclosed in 2023.