CVE-2024-9621: Insertion of Sensitive Information into Log File
A vulnerability was found in Quarkus CXF. Passwords and other secrets may appear in the application log in spite of the user configuring them to be hidden. This issue requires some special configuration to be vulnerable, such as SOAP logging enabled, application set client, and endpoint logging properties, and the attacker must have access to the application log.
AI Analysis
Technical Summary
The vulnerability identified as CVE-2024-9621 affects Quarkus CXF and involves the insertion of sensitive information, including passwords and secrets, into application log files. This occurs even when users configure these secrets to be hidden. The issue requires specific configurations to be vulnerable, including SOAP logging enabled, application set client, and endpoint logging properties. Exploitation requires the attacker to have access to the application logs. Red Hat has published advisories acknowledging the issue but currently does not offer a patch or mitigation that meets their standards for ease of use, applicability, or stability.
Potential Impact
Sensitive information such as passwords and secrets may be exposed in application logs, potentially allowing an attacker with access to these logs to obtain confidential data. The vulnerability does not affect integrity or availability but has a high confidentiality impact. Exploitation requires network access, low privileges, and no user interaction, but with high attack complexity due to the required configuration and log access.
Mitigation Recommendations
Red Hat currently states that no mitigation or patch meeting their criteria for ease of use, applicability, or stability is available. Users should be aware of the conditions that enable this vulnerability, such as enabling SOAP logging and specific client and endpoint logging configurations, and restrict access to application logs to trusted parties. Monitoring and controlling log access is critical until a fix is released. Users should follow Red Hat advisories for updates and apply patches once available.
CVE-2024-9621: Insertion of Sensitive Information into Log File
Description
A vulnerability was found in Quarkus CXF. Passwords and other secrets may appear in the application log in spite of the user configuring them to be hidden. This issue requires some special configuration to be vulnerable, such as SOAP logging enabled, application set client, and endpoint logging properties, and the attacker must have access to the application log.
CVSS v3.1
Score 5.3medium
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability identified as CVE-2024-9621 affects Quarkus CXF and involves the insertion of sensitive information, including passwords and secrets, into application log files. This occurs even when users configure these secrets to be hidden. The issue requires specific configurations to be vulnerable, including SOAP logging enabled, application set client, and endpoint logging properties. Exploitation requires the attacker to have access to the application logs. Red Hat has published advisories acknowledging the issue but currently does not offer a patch or mitigation that meets their standards for ease of use, applicability, or stability.
Potential Impact
Sensitive information such as passwords and secrets may be exposed in application logs, potentially allowing an attacker with access to these logs to obtain confidential data. The vulnerability does not affect integrity or availability but has a high confidentiality impact. Exploitation requires network access, low privileges, and no user interaction, but with high attack complexity due to the required configuration and log access.
Mitigation Recommendations
Red Hat currently states that no mitigation or patch meeting their criteria for ease of use, applicability, or stability is available. Users should be aware of the conditions that enable this vulnerability, such as enabling SOAP logging and specific client and endpoint logging configurations, and restrict access to application logs to trusted parties. Monitoring and controlling log access is critical until a fix is released. Users should follow Red Hat advisories for updates and apply patches once available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2024-10-08T01:08:43.306Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/errata/RHSA-2024:10035","vendor":"Red Hat"},{"url":"https://access.redhat.com/security/cve/CVE-2024-9621","vendor":"Red Hat"}]
Threat ID: 691f82024f1c50aa2eb5aeb3
Added to database: 11/20/2025, 21:02:58 UTC
Last enriched: 08/09/2026, 12:56:30 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 303
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.