Password in config file in KIE server
Critical severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Feb 14, 2023
Package
Affected versions
< 7.21.0.Final
Patched versions
7.21.0.Final
Description
Published by the National Vulnerability Database
May 15, 2019
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Feb 14, 2023
Reviewed
Feb 14, 2023
It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any app deployed on the same server would have access to these properties, thus granting access to ther services.
References