Skip to content

Conversation

@Revolyssup
Copy link
Contributor

- Vulnerability
description: Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when log level is INFO/DEBUG. This creates a high risk of credential compromise through log access.
tags: [Vulnerabilities]
image: https://static.apiseven.com/uploads/2024/05/06/Wq940JRt_CVE-2024-32638.png
Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@kayx23 Can you help update it to new image?


## Vulnerability details

Severity: Moderate
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

not translated

as well as the titles

@kayx23 kayx23 requested a review from Yilialinn October 31, 2025 07:14

Vulnerability public date: October 30, 2025

CVE details: https://nvd.nist.gov/vuln/detail/CVE-2025-62232
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Image

kayx23
kayx23 previously approved these changes Oct 31, 2025
@kayx23 kayx23 requested a review from juzhiyuan October 31, 2025 09:30
@kayx23 kayx23 dismissed their stale review November 1, 2025 06:14

content in the link says not found still

@yzeng25 yzeng25 requested review from juzhiyuan and kayx23 November 6, 2025 01:48
@kayx23 kayx23 merged commit 43e7984 into apache:master Nov 6, 2025
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants