CVE-2024-40636
Last modified
CVE-2024-40636 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Steeltoe is an open source project that provides a collection of libraries that helps users build production-grade cloud-native applications using externalized configuration, service discovery, distributed tracing, application management, and more. When utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
Steeltoe is an open source project that provides a collection of libraries that helps users build production-grade cloud-native applications using externalized configuration, service discovery, distributed tracing, application management, and more. When utilizing multiple Eureka server service URLs with basic auth and encountering an issue with fetching the service registry, an error is logged with the Eureka server service URLs but only the first URL is masked. The code in question is `_logger.LogError(e, "FetchRegistry Failed for Eureka service urls: {EurekaServerServiceUrls}", new Uri(ClientConfig.EurekaServerServiceUrls).ToMaskedString());` in the `DiscoveryClient.cs` file which may leak credentials into logs. This issue has been addressed in version 3.2.8 of the Steeltoe.Discovery.Eureka nuget package.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-40636?
How severe is CVE-2024-40636?
How do I fix CVE-2024-40636?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-40630OpenImageIO is a toolset for reading, writing, and manipulat…4.3
- CVE-2024-40631Plate media is an open source, rich-text editor for React. E…8.1
- CVE-2024-40632Linkerd is an open source, ultralight, security-first servic…3.7
- CVE-2024-40633Sylius is an Open Source eCommerce Framework on Symfony. A s…5.3
- CVE-2024-40634Argo CD is a declarative, GitOps continuous delivery tool fo…7.5
- CVE-2024-40635containerd is an open-source container runtime. A bug was fo…7.8
- CVE-2024-40637dbt enables data analysts and engineers to transform their d…7.8
- CVE-2024-40638GLPI is a free asset and IT management software package. An …8.8
- CVE-2024-40639Rejected reason: This CVE is a duplicate of another CVE.
- CVE-2024-4064A vulnerability was found in Tenda AC8 16.03.34.09. It has b…8.8
- CVE-2024-40640vodozemac is an open source implementation of Olm and Megolm…2.9
- CVE-2024-40641Nuclei is a fast and customizable vulnerability scanner base…7.4
Are you affected by CVE-2024-40636?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
