CVE-2023-0815
OpenNMS has potential Insertion of Sensitive Information into Log File vulnerability
6.5
MEDIUM
CVSS 3.1
EPSS 0.33%
Description
Potential Insertion of Sensitive Information into Jetty Log Files in multiple versions of OpenNMS Meridian and Horizon could allow disclosure of usernames and passwords if the logging level is set to debug.
How to fix CVE-2023-0815
To remediate CVE-2023-0815, upgrade the affected package to a fixed version below.
- —upgrade to 31.0.4 or later
Is CVE-2023-0815 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 31.0.4
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |