CVE-2024-3165: dotCMS
Medium severity, CVSS 4.5. EPSS: 0.5% chance of exploitation in the next 30 days.
System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it requires a backend admin as well as that dbs are locked down by environment. OWASP Top 10 - A05) Insecure Design OWASP Top 10 - A05) Security Misconfiguration OWASP Top 10 - A09) Security Logging and Monitoring Failure
Affected products
- dotCMS dotCMS: from 22.02, before 22.03.15 (fixed in 22.03.15); from 23.01, before 23.01.15 (fixed in 23.01.15); from 23.02, up to and including 23.09.7; version 23.10.24 only
Published 2024-04-01. Last modified 2026-06-17.