{"id":"CVE-2024-3165","summary":"Database Credential Exposure in the Logs","details":"System-\u003eMaintenance-\u003e Log Files in dotCMS dashboard is providing the username/password for database connections in the log output. Nevertheless, this is a moderate issue as it requires a backend admin as well as that dbs are locked down by environment.  \n\nOWASP Top 10 - A05) Insecure Design\n\nOWASP Top 10 - A05) Security Misconfiguration\n\nOWASP Top 10 - A09) Security Logging and Monitoring Failure","modified":"2026-08-12T03:51:31.617479197Z","published":"2024-04-01T21:38:04.085Z","database_specific":{"cna_assigner":"dotCMS","cwe_ids":["CWE-532"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/3xxx/CVE-2024-3165.json"},"references":[{"type":"WEB","url":"https://www.dotcms.com/security/SI-70"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/3xxx/CVE-2024-3165.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-3165"},{"type":"REPORT","url":"https://github.com/dotCMS/core/issues/27910"},{"type":"FIX","url":"https://github.com/dotCMS/core/pull/28006"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dotcms/core","events":[{"introduced":"a7dc7c4140d33d98ccc65120f9d659d07ad42ce0"},{"fixed":"cc51d80d4145ee517c981a5e9b7b5399ca3dfca3"},{"introduced":"9106fff61c040ca47230b318b1cf78cd0fcc49d2"},{"fixed":"4d47a41b27d9e50ad799b37b2f7cfc8fe99f02e1"},{"introduced":"3feb6fa6ebdcf1509252fbf9ee7e53017c8bf96f"},{"last_affected":"20de9e9f791d40b6655c3cd506d74fce8fcb4f2d"},{"introduced":"e32f4c872fbd0576ce4587aacaa26cc2995b9ce5"},{"last_affected":"c5e93f4fd71de3c021ba5cee5b2ffb1b6cbd414f"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:dotcms:dotcms:*:*:*:*:*:*:*:*","cpe:2.3:a:dotcms:dotcms:23.10.24:1:*:*:lts:*:*:*","cpe:2.3:a:dotcms:dotcms:23.10.24:2:*:*:lts:*:*:*","cpe:2.3:a:dotcms:dotcms:23.10.24:3:*:*:lts:*:*:*","cpe:2.3:a:dotcms:dotcms:23.10.24:4:*:*:lts:*:*:*","cpe:2.3:a:dotcms:dotcms:23.10.24:5:*:*:lts:*:*:*","cpe:2.3:a:dotcms:dotcms:23.10.24:6:*:*:lts:*:*:*","cpe:2.3:a:dotcms:dotcms:23.10.24:7:*:*:lts:*:*:*"],"extracted_events":[{"introduced":"22.02"},{"fixed":"22.03.15"},{"introduced":"23.01"},{"fixed":"23.01.15"},{"introduced":"23.02"},{"last_affected":"23.09.7"},{"introduced":"23.10.24-1"},{"last_affected":"23.10.24-1"},{"introduced":"23.10.24-2"},{"last_affected":"23.10.24-2"},{"introduced":"23.10.24-3"},{"last_affected":"23.10.24-3"},{"introduced":"23.10.24-4"},{"last_affected":"23.10.24-4"},{"introduced":"23.10.24-5"},{"last_affected":"23.10.24-5"},{"introduced":"23.10.24-6"},{"last_affected":"23.10.24-6"},{"introduced":"23.10.24-7"},{"last_affected":"23.10.24-7"}]}}],"versions":["22.02 and after","23.10.24-1","23.10.24-2","23.10.24-3","23.10.24-4","23.10.24-5","23.10.24-6","23.10.24-7","v23.01.14","v23.01.13","v23.01.12","v23.01.11","v23.01.10","v23.01.9","v23.01.8","v23.01.7","v23.01.6","v23.01.5","v23.01.4","v23.01.3","v23.01.2","v23.01.1","v23.01"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-3165.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N"}]}