Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-3165

System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it requires a backend admin as well as that dbs are locked down by environment.   OWASP Top 10 - A05) Insecure Design OWASP Top 10 - A05) Security Misconfiguration OWASP Top 10 - A09) Security Logging and Monitoring Failure
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 31.9%
CVSS Severity
CVSS v3 Score 4.5
Products affected by CVE-2024-3165
  • Dotcms » Dotcms » Version: 22.02
    cpe:2.3:a:dotcms:dotcms:22.02
  • Dotcms » Dotcms » Version: 22.03
    cpe:2.3:a:dotcms:dotcms:22.03
  • Dotcms » Dotcms » Version: 22.03.1
    cpe:2.3:a:dotcms:dotcms:22.03.1
  • Dotcms » Dotcms » Version: 22.03.10
    cpe:2.3:a:dotcms:dotcms:22.03.10
  • Dotcms » Dotcms » Version: 22.03.11
    cpe:2.3:a:dotcms:dotcms:22.03.11
  • Dotcms » Dotcms » Version: 22.03.12
    cpe:2.3:a:dotcms:dotcms:22.03.12
  • Dotcms » Dotcms » Version: 22.03.13
    cpe:2.3:a:dotcms:dotcms:22.03.13
  • Dotcms » Dotcms » Version: 22.03.14
    cpe:2.3:a:dotcms:dotcms:22.03.14
  • Dotcms » Dotcms » Version: 22.03.2
    cpe:2.3:a:dotcms:dotcms:22.03.2
  • Dotcms » Dotcms » Version: 22.03.4
    cpe:2.3:a:dotcms:dotcms:22.03.4
  • Dotcms » Dotcms » Version: 22.03.5
    cpe:2.3:a:dotcms:dotcms:22.03.5
  • Dotcms » Dotcms » Version: 22.03.6
    cpe:2.3:a:dotcms:dotcms:22.03.6
  • Dotcms » Dotcms » Version: 22.03.7
    cpe:2.3:a:dotcms:dotcms:22.03.7
  • Dotcms » Dotcms » Version: 22.03.8
    cpe:2.3:a:dotcms:dotcms:22.03.8
  • Dotcms » Dotcms » Version: 22.03.9
    cpe:2.3:a:dotcms:dotcms:22.03.9
  • Dotcms » Dotcms » Version: 23.01
    cpe:2.3:a:dotcms:dotcms:23.01
  • Dotcms » Dotcms » Version: 23.01.1
    cpe:2.3:a:dotcms:dotcms:23.01.1
  • Dotcms » Dotcms » Version: 23.01.10
    cpe:2.3:a:dotcms:dotcms:23.01.10
  • Dotcms » Dotcms » Version: 23.01.11
    cpe:2.3:a:dotcms:dotcms:23.01.11
  • Dotcms » Dotcms » Version: 23.01.12
    cpe:2.3:a:dotcms:dotcms:23.01.12
  • Dotcms » Dotcms » Version: 23.01.13
    cpe:2.3:a:dotcms:dotcms:23.01.13
  • Dotcms » Dotcms » Version: 23.01.14
    cpe:2.3:a:dotcms:dotcms:23.01.14
  • Dotcms » Dotcms » Version: 23.01.2
    cpe:2.3:a:dotcms:dotcms:23.01.2
  • Dotcms » Dotcms » Version: 23.01.3
    cpe:2.3:a:dotcms:dotcms:23.01.3
  • Dotcms » Dotcms » Version: 23.01.4
    cpe:2.3:a:dotcms:dotcms:23.01.4
  • Dotcms » Dotcms » Version: 23.01.5
    cpe:2.3:a:dotcms:dotcms:23.01.5
  • Dotcms » Dotcms » Version: 23.01.6
    cpe:2.3:a:dotcms:dotcms:23.01.6
  • Dotcms » Dotcms » Version: 23.01.7
    cpe:2.3:a:dotcms:dotcms:23.01.7
  • Dotcms » Dotcms » Version: 23.01.8
    cpe:2.3:a:dotcms:dotcms:23.01.8
  • Dotcms » Dotcms » Version: 23.01.9
    cpe:2.3:a:dotcms:dotcms:23.01.9
  • Dotcms » Dotcms » Version: 23.02
    cpe:2.3:a:dotcms:dotcms:23.02
  • Dotcms » Dotcms » Version: 23.03
    cpe:2.3:a:dotcms:dotcms:23.03
  • Dotcms » Dotcms » Version: 23.05
    cpe:2.3:a:dotcms:dotcms:23.05
  • Dotcms » Dotcms » Version: 23.06
    cpe:2.3:a:dotcms:dotcms:23.06
  • Dotcms » Dotcms » Version: 23.07
    cpe:2.3:a:dotcms:dotcms:23.07
  • Dotcms » Dotcms » Version: 23.08.16
    cpe:2.3:a:dotcms:dotcms:23.08.16
  • Dotcms » Dotcms » Version: 23.09.7
    cpe:2.3:a:dotcms:dotcms:23.09.7
  • Dotcms » Dotcms » Version: 23.10.24
    cpe:2.3:a:dotcms:dotcms:23.10.24


Contact Us

Shodan ® - All rights reserved