Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withdraw the unencrypted tokens with security implications, such as unauthorized access, session hijacking, and information disclosure.
History

Fri, 18 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Jul 2025 22:00:00 +0000

Type Values Removed Values Added
Description Brocade ASCG before 3.3.0 logs JSON Web Tokens (JWT) in log files. An attacker with access to the log files can withdraw the unencrypted tokens with security implications, such as unauthorized access, session hijacking, and information disclosure.
Title JSON Web Token (JWT) Exposure in Log Files
Weaknesses CWE-532
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: brocade

Published: 2025-07-17T21:45:27.024Z

Updated: 2025-07-18T14:11:11.224Z

Reserved: 2025-06-20T02:59:00.845Z

Link: CVE-2025-6391

cve-icon Vulnrichment

Updated: 2025-07-18T14:11:07.987Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-17T22:15:26.263

Modified: 2025-07-22T13:06:27.983

Link: CVE-2025-6391

cve-icon Redhat

No data.