Vulnerability record · CVE-2024-3165 · published 1 April 2024
CVE-2024-3165: Dotcms sensitive information in log file vulnerability
Dotcms · Dotcms
System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it requires a backend admin as well as that dbs are locked down by environment. OWASP Top 10 - A05) Insecure Design OWASP Top 10 - A05) Security Misconfiguration OWASP Top 10 - A09) Security Logging and Monitoring Failure
Description
System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it requires a backend admin as well as that dbs are locked down by environment. OWASP Top 10 - A05) Insecure Design OWASP Top 10 - A05) Security Misconfiguration OWASP Top 10 - A09) Security Logging and Monitoring Failure
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/dotCMS/core/issues/27910 | Issue Tracking |
| https://github.com/dotCMS/core/pull/28006 | Issue Tracking |
| https://www.dotcms.com/security/SI-70 | Broken Link |
| https://github.com/dotCMS/core/issues/27910 | Issue Tracking |
| https://github.com/dotCMS/core/pull/28006 | Issue Tracking |
| https://www.dotcms.com/security/SI-70 | Broken Link |
Track CVE-2024-3165 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-3165), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.