Quarkus CXF Vulnerability: Hidden Passwords and Secrets at Risk
CVE-2024-9621
Key Information:
- Vendor
- CVE Published:
- 8 October 2024
What is CVE-2024-9621?
A security issue exists in Quarkus CXF where sensitive information like passwords can be inadvertently logged, despite user configurations intended to keep these details hidden. This vulnerability requires specific configurations to be exposed, including the enablement of SOAP logging, along with the presence of user-set client and endpoint logging properties. Attackers with access to the application logs can exploit this flaw for unauthorized data access, highlighting the importance of stringent logging practices in application security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
