Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Teamcity MEDIUM 6.5
CVE-2023-38067

In JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent log

Fix: 2023.05.1+
Fix from $1,600 2023-07-12
Mobile Security HIGH 7.5
CVE-2023-35695

A remote attacker could leverage a vulnerability in Trend Micro Mobile Security (Enterprise) 9.8 SP5 to download a particular log file which may cont…

Patch available
Fix from $1,950 2023-06-26
Ipados MEDIUM 5.5
CVE-2023-32392

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4…

Fix: 9.5 / 11.7.7+
Fix from $1,600 2023-06-23
Cloud Foundry Nfs Volume MEDIUM 6.5
CVE-2023-20885

Vulnerability in Cloud Foundry Notifications, Cloud Foundry SMB-volume release, Cloud FOundry cf-nfs-volume release.This issue affects Notifications:…

Fix: 3.1.19 / 5.0.27+
Fix from $1,600 2023-06-16
Fortiproxy MEDIUM 6.5
CVE-2023-26207

An insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.2.0 through 7.2.4 and FortiProxy 7.0.0 through 7.0.10. 7.2.0 …

Fix: after 7.2.4
Fix from $1,600 2023-06-13
Secrets Store Csi Driver MEDIUM 5.5
CVE-2023-2878

Kubernetes secrets-store-csi-driver in versions before 1.3.3 discloses service account tokens in logs.

Fix: 1.3.3+
Fix from $1,600 2023-06-07
Hoppscotch HIGH 8.8
CVE-2023-34097

hoppscotch is an open source API development ecosystem. In versions prior to 2023.4.5 the database password is exposed in the logs when showing the d…

Fix: 2023.4.5+
Fix from $1,950 2023-06-05
Teamcity MEDIUM 5.3
CVE-2023-34223

In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases

Fix: 2023.05+
Fix from $1,600 2023-05-31
Platform Engineering Tools MEDIUM 5.5
CVE-2022-0010

Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering Tools. An attacker, who al…

Fix: after 6.1.0
Fix from $1,600 2023-05-22
Hashicorp Vault HIGH 7.5
CVE-2023-33001

Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when…

Fix: after 360.v0a_1c04cf807d
Fix from $1,950 2023-05-16
Mattermost HIGH 7.5
CVE-2023-2514

Mattermost Sever fails to redact the DB username and password before emitting an application log during server initialization. 

Fix: after 7.9.1
Fix from $1,950 2023-05-12
Checkmk MEDIUM 5.5
CVE-2023-31207

Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause the automation user's secret…

Mitigation only
Fix from $1,600 2023-05-02
Cloud Init MEDIUM 5.5
CVE-2023-1786

Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and poss…

Fix: 23.1.2+
Fix from $1,600 2023-04-26
Cloverdx MEDIUM 6.5
CVE-2023-31056

CloverDX before 5.17.3 writes passwords to the audit log in certain situations, if the audit log is enabled and single sign-on is not employed. The f…

Fix: 5.17.3+
Fix from $1,600 2023-04-24
Cloud Init MEDIUM 5.5
CVE-2021-3429

When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log…

Fix: 21.2+
Fix from $1,600 2023-04-19
Cloud Init MEDIUM 5.5
CVE-2022-2084

Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include h…

Fix: 22.3+
Fix from $1,600 2023-04-19
Aws Sigv4 MEDIUM 5.5
CVE-2023-30610

aws-sigv4 is a rust library for low level request signing in the aws cloud platform. The `aws_sigv4::SigningParams` struct had a derived `Debug` impl…

Mitigation only
Fix from $1,600 2023-04-19
Cilium MEDIUM 6.3
CVE-2023-29002

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. When run in debug mode, Cilium will log the contents of th…

Fix: 1.11.16 / 1.12.9+
Fix from $1,600 2023-04-18
Acuant Asureid Sentinel MEDIUM 5.5
CVE-2022-48228

An issue was discovered in Acuant AsureID Sentinel before 5.2.149. It uses the root of the C: drive for the i-Dentify and Sentinel Installer log file…

Fix: 5.2.149+
Fix from $1,600 2023-04-04
Vantara Pentaho Business Analytics Server MEDIUM 6.5
CVE-2022-43772

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Data Plugin expose the username a…

Fix: 9.3.0.1+
Fix from $1,600 2023-04-03
Nginx Agent MEDIUM 5.5
CVE-2023-1550

Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information in…

Fix: 2.9.0 / 2.23.3+
Fix from $1,600 2023-03-29
Veracode MEDIUM 6.5
CVE-2023-25721

Veracode Scan Jenkins Plugin before 23.3.19.0, when the "Connect using proxy" option is enabled and configured with proxy credentials and when the Je…

Fix: 23.3.19.0+
Fix from $1,600 2023-03-28
Openshift Assisted Installer MEDIUM 5.5
CVE-2021-3684

A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the…

Fix: 1.0.25.3+
Fix from $1,600 2023-03-24
Smartcars 3 HIGH 7.5
CVE-2023-28441

smartCARS 3 is flight tracking software. In version 0.5.8 and prior, all persons who have failed login attempts will have their password stored in er…

Fix: 0.5.9+
Fix from $1,950 2023-03-24
Directus MEDIUM 5.5
CVE-2023-28443

Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.23.3, the `directus_refresh_token` is not redacte…

Fix: 9.23.3+
Fix from $1,600 2023-03-24
Spring Cloud Config MEDIUM 5.5
CVE-2023-20859

In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sen…

Fix: 2.3.3 / 3.0.2+
Fix from $1,600 2023-03-23
Freshrss MEDIUM 5.5
CVE-2023-22481

FreshRSS is a self-hosted RSS feed aggregator. When using the greader API, the provided password is logged in clear in `users/_/log_api.txt` in the c…

Fix: 1.21.0+
Fix from $1,600 2023-03-06
Maximo Application Suite MEDIUM 5.5
CVE-2022-43923

IBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be read by a local user. IBM X-Force ID: 241584.

Mitigation only
Fix from $1,600 2023-02-24
Horizon MEDIUM 6.5
CVE-2023-0815

Potential Insertion of Sensitive Information into Jetty Log Files in multiple versions of OpenNMS Meridian and Horizon could allow disclosure of user…

Fix: 31.0.4 / 2023.1.0+
Fix from $1,600 2023-02-23
Spectrum Virtualize MEDIUM 6.5
CVE-2022-43870

IBM Spectrum Virtualize 8.3, 8.4, and 8.5 could disclose SNMPv3 server credentials to an authenticated user in log files. IBM X-Force ID: 239540.

Mitigation only
Fix from $1,600 2023-02-22