OWASP Top 10 - A05) Insecure Design
OWASP Top 10 - A05) Security Misconfiguration
OWASP Top 10 - A09) Security Logging and Monitoring Failure
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-31762 | System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it requires a backend admin as well as that dbs are locked down by environment. OWASP Top 10 - A05) Insecure Design OWASP Top 10 - A05) Security Misconfiguration OWASP Top 10 - A09) Security Logging and Monitoring Failure |
Fri, 27 Jun 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:dotcms:dotcms:23.10.24:1:*:*:lts:*:*:* cpe:2.3:a:dotcms:dotcms:23.10.24:2:*:*:lts:*:*:* cpe:2.3:a:dotcms:dotcms:23.10.24:3:*:*:lts:*:*:* cpe:2.3:a:dotcms:dotcms:23.10.24:4:*:*:lts:*:*:* cpe:2.3:a:dotcms:dotcms:23.10.24:5:*:*:lts:*:*:* cpe:2.3:a:dotcms:dotcms:23.10.24:6:*:*:lts:*:*:* cpe:2.3:a:dotcms:dotcms:23.10.24:7:*:*:lts:*:*:* |
Mon, 30 Sep 2024 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-522 |
Mon, 30 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dotcms
Dotcms dotcms |
|
| CPEs | cpe:2.3:a:dotcms:dotcms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Dotcms
Dotcms dotcms |
|
| Metrics |
ssvc
|
Mon, 30 Sep 2024 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-532 |
Status: PUBLISHED
Assigner: dotCMS
Published:
Updated: 2024-09-30T15:27:54.804Z
Reserved: 2024-04-01T21:31:06.377Z
Link: CVE-2024-3165
Updated: 2024-08-01T20:05:07.539Z
Status : Analyzed
Published: 2024-04-01T22:15:23.080
Modified: 2025-06-27T14:06:33.077
Link: CVE-2024-3165
No data.
OpenCVE Enrichment
No data.
EUVD