5
CVSSv2

CVE-2010-3845

Published: 08/08/2017 Updated: 18/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

libapache-authenhook-perl 2.00-04 stores usernames and passwords in plaintext in the vhost error log.

Vulnerable Product Search on Vulmon Subscribe to Product

apache authenhook project apache authenhook 2.00-04

Vendor Advisories

Debian Bug report logs - #599712 libapache-authenhook-perl: leaks passwords to the logs Package: libapache-authenhook-perl; Maintainer for libapache-authenhook-perl is Debian Perl Group <pkg-perl-maintainers@listsaliothdebianorg>; Source for libapache-authenhook-perl is src:libapache-authenhook-perl (PTS, buildd, popcon) ...