Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8 exposes both access and secret keys in logs without redaction. These credentials are later reused in variable assignments for persistence but do not require logging for debugging or system health purposes. Version 1.50.8 fixes the issue.
Metrics
Affected Vendors & Products
References
History
Mon, 02 Jun 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 02 Jun 2025 11:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Para is a multitenant backend server/framework for object persistence and retrieval. A vulnerability that exists in versions prior to 1.50.8 exposes both access and secret keys in logs without redaction. These credentials are later reused in variable assignments for persistence but do not require logging for debugging or system health purposes. Version 1.50.8 fixes the issue. | |
Title | Para Server Logs Sensitive Information | |
Weaknesses | CWE-532 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-06-02T11:11:22.722Z
Updated: 2025-06-02T16:47:02.156Z
Reserved: 2025-05-28T18:49:07.585Z
Link: CVE-2025-48955

Updated: 2025-06-02T16:46:39.998Z

Status : Awaiting Analysis
Published: 2025-06-02T12:15:25.523
Modified: 2025-06-02T17:32:17.397
Link: CVE-2025-48955

No data.