PT-2026-84831 · Boruta · Boruta
CVE-2026-55221
·
Published
2026-09-02
·
Updated
2026-09-02
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Boruta versions prior to 0.10.0
Description
Boruta, a standalone authorization server implementing OAuth 2.0 and OpenID Connect, improperly records sensitive values in business event logs. This includes access tokens, refresh tokens, authorization codes, agent tokens, direct-post codes, ID tokens, VP tokens, and tokens sent to introspection or revocation endpoints. An attacker with access to the logs, log aggregation systems, or the administration log viewer could recover these credentials and use them until they expire or are revoked.
Recommendations
Update to version 0.10.0.
Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Boruta