GHSA-3jh5-rr2q-xfv7 is a high-severity (CVSS 7.6) CWE-532 vulnerability in com.ritense.valtimo:web. O3 Security confirms whether GHSA-3jh5-rr2q-xfv7 is actually reachable in your code before you act, and blocks exploitation at runtime until you patch.
Valtimo has sensitive data exposure through HTTP request/response logging in LoggingRestClientCustomizer
Exploitation Status
No confirmed exploitation observed yet
- CISA’s own triage has not observed active exploitation or public proof-of-concept code for this CVE as of its last assessment.
Exploitation and automatability from CISA’s SSVC triage for GHSA-3jh5-rr2q-xfv7.
EPSS Exploitation Probability
EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.
How urgent is this, really
GHSA-3jh5-rr2q-xfv7 plotted by exploitation likelihood (EPSS) against impact (CVSS). The shaded corner — EPSS 50%+ and CVSS 7.0+ — is where this CVE doesn't sit, though severity or exploitability alone can still warrant action.
Where this sits among everything scored
Of 356,453 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Real counts from FIRST.org, not a sample — log-scaled since the landscape is heavily right-skewed.
Real-World Exposure
com.ritense.valtimo:web☕com.ritense.valtimo:webReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects Maven packages — download data is not available via public APIs for these ecosystems.
Description
Summary
The LoggingRestClientCustomizer in the web module automatically intercepts all outgoing HTTP calls made via Spring's RestClient and logs the full request body, response body, and response headers. When an error response is received, this information is included in the thrown HttpClientErrorException message, which is logged at ERROR level by Spring's default exception handling — regardless of the application's DEBUG log level setting.
Impact
The logged data can contain highly sensitive information including:
- Authentication credentials (JWT tokens, API keys, OAuth tokens) in request bodies or response headers
- Personal data (BSN, email addresses, case details) in request/response bodies
- Session tokens in
Set-Cookieresponse headers
This data is exposed to:
- Anyone with access to application logs (stdout/log files)
- Users with access to logging aggregation tools (e.g. Grafana/Loki)
- Any Valtimo user with the admin role, through the built-in logging module (since Valtimo 12.5.0)
Leaked authentication credentials could be used to impersonate the Valtimo application against the target external API (e.g. ZGW services), compromising that API's security boundary.
Related: GHSA-hfrg-mcvw-8mch (similar sensitive data exposure in InboxHandlingService)
Affected Code
com.ritense.valtimo.web.logging.LoggingRestClientCustomizer#intercept in the web module.
Patched Versions
The vulnerability is fixed in:
- 12.33.0 (v12 release line) — see PR #600
- 13.26.0 (v13 release line) — see PR #599
The fix removes the request/response report, headers, and response body from the HttpClientErrorException constructor; only the HTTP status code and status text remain. The full request/response report is still emitted at DEBUG level (disabled in production).
Mitigation
If you cannot upgrade to a patched version immediately, consider:
- Restricting access to application logs and the Valtimo logging module
- Adjusting the log level for
com.ritense.valtimo.web.loggingto WARN or higher (note: this only mitigates the DEBUG logging path; error responses still leak data via the exception message)
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| ☕Maven | com.ritense.valtimo:web | ≥ 12.4.0&&< 12.33.0 | 12.33.0 |
| ☕Maven | com.ritense.valtimo:web | ≥ 13.0.0&&< 13.26.0 | 13.26.0 |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for com.ritense.valtimo:web. O3's reachability analysis confirms whether the vulnerable code path is actually invoked in your application, so you act on real exposure instead of every transitive match.
Fix
Update com.ritense.valtimo:web to 12.33.0 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-3jh5-rr2q-xfv7 is resolved across your whole dependency graph.
Workarounds
If you can't upgrade right away: gate or disable the affected feature, validate untrusted input at the boundary, and avoid passing attacker-controlled data into the vulnerable path. O3's runtime protection blocks exploitation in production as an interim safeguard until the upgrade lands.
How O3 protects you
O3 pinpoints whether GHSA-3jh5-rr2q-xfv7 is reachable in your code and exactly where to fix it, then blocks exploitation in production at runtime until the patched version is deployed.
Tailored to GHSA-3jh5-rr2q-xfv7. Runtime protection reduces exposure until a permanent patch is applied and verified — it complements patching, it doesn't replace it.
Frequently Asked Questions
Is GHSA-3jh5-rr2q-xfv7 in your dependencies?
O3 detects GHSA-3jh5-rr2q-xfv7 across Maven dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.