We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-49009

Para Inserts Sensitive Information into Log File for Facebook authentication



Description

Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8 in `FacebookAuthFilter.java` results in a full request URL being logged during a failed request to a Facebook user profile. The log includes the user's access token in plain text. Since WARN-level logs are often retained in production and accessible to operators or log aggregation systems, this poses a risk of token exposure. Version 1.50.8 fixes the issue.

Reserved 2025-05-29 | Published 2025-06-05 | Updated 2025-06-05 | Assigner GitHub_M


MEDIUM: 6.2CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Problem types

CWE-532: Insertion of Sensitive Information into Log File

Product status

< 1.50.8
affected

References

github.com/...a/para/security/advisories/GHSA-qx7g-fx8q-545g

github.com/...ommit/46a908d887da02037384193f70a69345f04887cf

cve.org (CVE-2025-49009)

nvd.nist.gov (CVE-2025-49009)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-49009

Support options

Helpdesk Chat, Email, Knowledgebase