Brocade ASCG before 3.3.0 logs JSON
Web Tokens (JWT) in log files. An attacker with access to the log files
can withdraw the unencrypted tokens with security implications, such as
unauthorized access, session hijacking, and information disclosure.
Metrics
Affected Vendors & Products
References
History
Fri, 18 Jul 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 17 Jul 2025 22:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withdraw the unencrypted tokens with security implications, such as unauthorized access, session hijacking, and information disclosure. | |
Title | JSON Web Token (JWT) Exposure in Log Files | |
Weaknesses | CWE-532 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: brocade
Published: 2025-07-17T21:45:27.024Z
Updated: 2025-07-18T14:11:11.224Z
Reserved: 2025-06-20T02:59:00.845Z
Link: CVE-2025-6391

Updated: 2025-07-18T14:11:07.987Z

Status : Awaiting Analysis
Published: 2025-07-17T22:15:26.263
Modified: 2025-07-22T13:06:27.983
Link: CVE-2025-6391

No data.