CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-40636

Medium Severity
SVRS
30/100

CVSSv3
NA/10

EPSS
0.00035/1

CVE-2024-40636 is a vulnerability in Steeltoe's Eureka Discovery Client that can lead to credential exposure. Specifically, when the application fails to fetch the service registry using multiple Eureka server URLs with basic authentication, it logs an error message containing the unmasked credentials of the subsequent URLs after the first one. This credential leak occurs because only the first URL is masked, potentially exposing sensitive information in the application logs. With an SVRS score of 30, this vulnerability is not considered critical but should still be addressed to prevent unauthorized access. This issue can compromise the security of your cloud-native applications by allowing attackers to potentially obtain credentials from log files. Upgrade to Steeltoe.Discovery.Eureka version 3.2.8 or later to mitigate this risk. While the CVSS score is 0 the real-world implications make patching essential.

In The Wild
2024-07-17

2024-07-18

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

CVE-2024-40636 | SteeltoeOSS up to 3.2.7 Eureka Service DiscoveryClient.cs ToMaskedString log file
vuldb.com2024-07-17
CVE-2024-40636 | SteeltoeOSS up to 3.2.7 Eureka Service DiscoveryClient.cs ToMaskedString log file | A vulnerability was found in SteeltoeOSS up to 3.2.7. It has been declared as problematic. Affected by this vulnerability is the function ToMaskedString of the file DiscoveryClient.cs of the component Eureka Service. The manipulation leads to sensitive information in log files. This vulnerability is known as <a href
cve-2024-40636
domains
urls
cves

Social Media

CVE-2024-40636 Steeltoe is an open source project that provides a collection of libraries that helps users build production-grade cloud-native applications using externalized configuration, service discovery, dist... https://t.co/9OEQr90GrQ
0
0
0

Affected Software

No affected software found for this CVE

References

ReferenceLink
[email protected]https://github.com/SteeltoeOSS/security-advisories/security/advisories/GHSA-vmcp-66r5-3pcp
GITHUBhttps://github.com/SteeltoeOSS/security-advisories/security/advisories/GHSA-vmcp-66r5-3pcp

CWE Details

CWE IDCWE NameDescription
CWE-532Insertion of Sensitive Information into Log FileInformation written to log files can be of a sensitive nature and give valuable guidance to an attacker or expose sensitive user information.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence