Insertion of Sensitive Information into Log File Affecting com.ritense.valtimo:web package, versions [12.4.0.RELEASE,12.33.0.RELEASE)[13.0.0.RELEASE,13.26.0.RELEASE)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.2% (10th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Insertion of Sensitive Information into Log File vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JAVA-COMRITENSEVALTIMO-16700066
  • published15 May 2026
  • disclosed14 May 2026
  • creditUnknown

Introduced: 14 May 2026

CVE-2026-44516  (opens in a new tab)
CWE-532  (opens in a new tab)

How to fix?

Upgrade com.ritense.valtimo:web to version 12.33.0.RELEASE, 13.26.0.RELEASE or higher.

Overview

Affected versions of this package are vulnerable to Insertion of Sensitive Information into Log File in the LoggingRestClientCustomizer method. An attacker can access sensitive information by triggering HTTP requests that result in error responses, causing the full request body, response body, and response headers to be logged at the ERROR level.

CVSS Base Scores

version 4.0
version 3.1