The vendor explicitly identifies these products as affected by this CVE.
- log4j as a component of Red Hat Enterprise Linux 8
- log4j-jcl as a component of Red Hat Enterprise Linux 8
- log4j-slf4j as a component of Red Hat Enterprise Linux 8
- log4j-web as a component of Red Hat Enterprise Linux 8
- spring-cloud-config-server as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack
- Summary
- A flaw was found in Spring Cloud Config Server. When trace logging is enabled, sensitive information is inadvertently written in plain text to the logs. A highly privileged local user could exploit this vulnerability to gain unauthorized access to confidential data, leading to information disclosure.
- Remediation
- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
