Vulnerability index

Browse CVEs

909 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Kibana MEDIUM 6.5
CVE-2023-46675

An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error or in the event where debug …

Fix: 7.17.16 / 8.11.2+
Fix from $1,600 2023-12-13
Kibana MEDIUM 6.5
CVE-2023-46671

An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error. Elastic has released Kibana…

Fix: 8.11.1+
Fix from $1,600 2023-12-13
Elastic Beats MEDIUM 6.5
CVE-2023-49922

An issue was discovered by Elastic whereby Beats and Elastic Agent would log a raw event in its own logs at the WARN or ERROR level if ingesting that…

Fix: 7.17.16 / 8.11.3+
Fix from $1,600 2023-12-12
Elastic Agent MEDIUM 6.5
CVE-2023-6687

An issue was discovered by Elastic whereby Elastic Agent would log a raw event in its own logs at the WARN or ERROR level if ingesting that event to …

Fix: 7.17.16 / 8.11.3+
Fix from $1,600 2023-12-12
Enterprise Search MEDIUM 6.5
CVE-2023-49923

An issue was discovered by Elastic whereby the Documents API of App Search logged the raw contents of indexed documents at INFO log level. Depending …

Fix: 7.17.16 / 8.11.2+
Fix from $1,600 2023-12-12
Cryptospike CRITICAL 9.1
CVE-2023-36649

Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate…

No fix yet
Fix from $2,300 2023-12-12
Cloud Firestore MEDIUM 5.5
CVE-2023-6460

A potential logging of the firestore key via logging within nodejs-firestore exists - Developers who were logging objects through this._settings woul…

Fix: 6.1.0+
Fix from $1,600 2023-12-04
Checkmk Appliance Firmware MEDIUM 5.5
CVE-2023-6287

Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.8 allows local attacker to retrieve passwords via reading log files.

Fix: 1.6.8+
Fix from $1,600 2023-11-27
Shield MEDIUM 6.5
CVE-2023-48708

CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. In affected versions successful login attempts are recorded wit…

Patch available
Fix from $1,600 2023-11-24
Pandora Fms CRITICAL 9.8
CVE-2023-4677

Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs…

Fix: 773+
Fix from $2,300 2023-11-23
Sterling B2b Integrator MEDIUM 5.5
CVE-2023-25682

IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 stores potentially sensitive information in log file…

Fix: 6.0.3.9 / 6.1.2.3+
Fix from $1,600 2023-11-22
Logstash MEDIUM 5.5
CVE-2023-46672

An issue was identified by Elastic whereby sensitive information is recorded in Logstash logs under specific circumstances. The prerequisites for th…

Fix: 8.11.1+
Fix from $1,600 2023-11-15
On Demand MEDIUM 5.5
CVE-2023-32283

Insertion of sensitive information into log file in some Intel(R) On Demand software before versions 1.16.2, 2.1.1, 3.1.0 may allow an authenticated …

Mitigation only
Fix from $1,600 2023-11-14
Unison Software MEDIUM 5.5
CVE-2022-46647

Insertion of sensitive information into log file for some Intel Unison software may allow an authenticated user to potentially enable information dis…

Fix: 20.14.2.3053 / 20.14.4244+
Fix from $1,600 2023-11-14
Headscale HIGH 7.5
CVE-2023-47390

Headscale through 0.22.3 writes bearer tokens to info-level logs.

Fix: after 0.22.3
Fix from $1,950 2023-11-11
Atlas Kubernetes Operator HIGH 7.5
CVE-2023-0436

The affected versions of MongoDB Atlas Kubernetes Operator may print sensitive information like GCP service account keys and API integration secrets …

Fix: 1.7.1+
Fix from $1,950 2023-11-07
Spicedb MEDIUM 6.5
CVE-2023-46255

SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Prior to version 1.…

Fix: 1.27.0+
Fix from $1,600 2023-10-31
Airflow HIGH 7.5
CVE-2023-46215

Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow. Sensitive information logged as cl…

Fix: 2.7.0+
Fix from $1,950 2023-10-28
Kibana HIGH 7.5
CVE-2023-31422

An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. The issue impacts only Kibana v…

Mitigation only
Fix from $1,950 2023-10-26
Fleet Server HIGH 8.1
CVE-2023-46667

An issue was discovered in Fleet Server >= v8.10.0 and < v8.10.3 where Agent enrolment tokens are being inserted into the Fleet Server’s log file in …

Fix: 8.10.3+
Fix from $1,950 2023-10-26
Endpoint CRITICAL 9.1
CVE-2023-46668

If Elastic Endpoint (v7.9.0 - v8.10.3) is configured to use a non-default option in which the logging level is explicitly set to debug, and when Elas…

Fix: after 8.10.3
Fix from $2,300 2023-10-26
Ipados MEDIUM 5.5
CVE-2023-41254

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.1 and iPadOS 17.1, watchOS 10.1, iO…

Fix: 10.1 / 13.6.1+
Fix from $1,600 2023-10-25
Santuario Xml Security For Java MEDIUM 6.5
CVE-2023-44483

All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue whe…

Fix: 2.2.6 / 2.3.4+
Fix from $1,600 2023-10-20
Ydb Go Sdk MEDIUM 5.5
CVE-2023-45825

ydb-go-sdk is a pure Go native and database/sql driver for the YDB platform. Since ydb-go-sdk v3.48.6 if you use a custom credentials object (impleme…

Fix: 3.53.2+
Fix from $1,600 2023-10-19
Mattermost Desktop MEDIUM 5.5
CVE-2023-5339

Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including pa…

Fix: after 5.4.0
Fix from $1,600 2023-10-17
Fortiguest MEDIUM 5.5
CVE-2023-25604

An insertion of sensitive information into log file vulnerability in Fortinet FortiGuest 1.0.0 allows a local attacker to access plaintext passwords …

Mitigation only
Fix from $1,600 2023-10-10
Reachfar Gps Firmware HIGH 7.5
CVE-2023-5499

Information exposure vulnerability in Shenzhen Reachfar v28, the exploitation of which could allow a remote attacker to retrieve all the week's logs …

Mitigation only
Fix from $1,950 2023-10-10
Big Ip Domain Name System MEDIUM 5.5
CVE-2023-41253

When on BIG-IP DNS or BIG-IP LTM enabled with DNS Services License, and a TSIG key is created, it is logged in plaintext in the audit log.  Note: Sof…

Fix: 15.1.9 / 16.1.4+
Fix from $1,600 2023-10-10
Big Iq Centralized Management MEDIUM 5.5
CVE-2023-43485

When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log.  Note: Software version…

Fix: 8.2.0.1.0.13.97-eng / 8.3.0.0.12.118-eng+
Fix from $1,600 2023-10-10
Subiquity MEDIUM 5.5
CVE-2023-5182

Sensitive data could be exposed in logs of subiquity version 23.09.1 and earlier. An attacker in the adm group could use this information to find has…

Fix: after 23.09.1
Fix from $1,600 2023-10-07