CVE-2019-10212

Publication date 2 October 2019

Last updated 11 July 2025


Ubuntu priority

Cvss 3 Severity Score

4.8 · Medium

Score breakdown

Description

A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to obtain the user's credentials from the log files.

Status

Package Ubuntu Release Status
undertow 25.10 questing
Needs evaluation
25.04 plucky
Needs evaluation
24.10 oracular Ignored end of life, was needs-triage
24.04 LTS noble
Needs evaluation
23.10 mantic Not in release
23.04 lunar Not in release
22.10 kinetic
Not affected
22.04 LTS jammy
Not affected
21.10 impish
Not affected
21.04 hirsute
Not affected
20.10 groovy
Not affected
20.04 LTS focal
Not affected
19.10 eoan Ignored end of life
19.04 disco Ignored end of life
18.04 LTS bionic
Needs evaluation
16.04 LTS xenial
Needs evaluation
14.04 LTS trusty Not in release

Severity score breakdown

Parameter Value
Base score 4.8 · Medium
Attack vector Network
Attack complexity High
Privileges required High
User interaction Required
Scope Unchanged
Confidentiality High
Integrity impact Low
Availability impact None
Vector CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N