Descrição
When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these properties. This logging occurs without sufficient validation or sanitization of the property values. A malicious actor with access to the -wso2carbon- log files could retrieve sensitive information, such as user credentials or other confidential data, that was inadvertently logged due to misconfiguration, potentially leading to unauthorized access.
CVSS 4.4EPSS 0.11299999999999999%Risco 0.44
Ver fonte- Publicação
- 2026-08-06 08:16:29
- Última alteração
- 2026-08-06 15:31:57
- Vetor
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N