Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Big Ip Access Policy Manager MEDIUM 5.5
CVE-2020-5908

In versions bundled with BIG-IP APM 12.1.0-12.1.5 and 11.6.1-11.6.5.2, Edge Client for Linux exposes full session ID in the local log files.

Fix: after 12.1.5
Fix from $1,600 2020-07-01
Jaeger MEDIUM 5.5
CVE-2020-10750

Sensitive information written to a log file vulnerability was found in jaegertracing/jaeger before version 1.18.1 when the Kafka data store is used. …

Fix: 1.18.1+
Fix from $1,600 2020-06-19
Octopus Deploy MEDIUM 6.5
CVE-2020-14470

In Octopus Deploy 2018.8.0 through 2019.x before 2019.12.2, an authenticated user with could trigger a deployment that leaks the Helm Chart repositor…

Fix: 2019.12.2+
Fix from $1,600 2020-06-19
Mattermost Mobile HIGH 7.5
CVE-2019-20852

An issue was discovered in Mattermost Mobile Apps before 1.26.0. Local logging is not blocked for sensitive information (e.g., server addresses or me…

Fix: 1.26.0+
Fix from $1,950 2020-06-19
Spectrum Protect Plus MEDIUM 6.5
CVE-2020-4477

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 discloses highly sensitive information in plain text in the virgo log file which could be used in fur…

Fix: after 10.1.5
Fix from $1,600 2020-06-15
Openshift Container Platform HIGH 7.5
CVE-2020-10752

A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server pa…

Patch available
Fix from $1,950 2020-06-12
Vault HIGH 7.5
CVE-2020-13223

HashiCorp Vault and Vault Enterprise logged proxy environment variables that potentially included sensitive credentials. Fixed in 1.3.6 and 1.4.2.

Fix: 1.3.6 / 1.4.2+
Fix from $1,950 2020-06-10
Debian Linux HIGH 7.5
CVE-2020-13881

In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used.

Fix: 2020.1.2+
Fix from $1,950 2020-06-06
Android HIGH 7.5
CVE-2020-13830

An issue was discovered on Samsung mobile devices with P(9.0) software. One UI HOME logging can leak information. The Samsung ID is SVE-2019-16382 (J…

Mitigation only
Fix from $1,950 2020-06-04
Debugbar CRITICAL 9.8
CVE-2020-11094

The October CMS debugbar plugin before version 3.1.0 contains a feature where it will log all requests (and all information pertaining to each reques…

Fix: 3.1.0+
Fix from $2,300 2020-06-04
Digital Network Architecture Center HIGH 8.8
CVE-2020-3281

A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to vi…

Fix: 1.3.3.3+
Fix from $1,950 2020-06-03
Broker HIGH 7.5
CVE-2020-7654

All versions of snyk-broker before 4.73.1 are vulnerable to Information Exposure. It logs private keys if logging level is set to DEBUG.

Fix: 4.73.1+
Fix from $1,950 2020-05-29
Globalprotect MEDIUM 5.5
CVE-2020-2004

Under certain circumstances a user's password may be logged in cleartext in the PanGPS.log diagnostic file when logs are collected for troubleshootin…

Fix: 5.0.9 / 5.1.2+
Fix from $1,600 2020-05-13
Keycloak MEDIUM 5.5
CVE-2020-1698

A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highe…

Fix: 9.0.0+
Fix from $1,600 2020-05-11
Openshift Container Platform HIGH 8.2
CVE-2020-10712

A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry operator a…

Fix: after 4.1
Fix from $1,950 2020-04-22
Iqrouter Firmware HIGH 7.5
CVE-2020-11968

In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control. Note: The vendor claims that t…

Fix: after 3.3.1
Fix from $1,950 2020-04-21
Netweaver Application Server Java MEDIUM 6.2
CVE-2020-6224

SAP NetWeaver AS Java (HTTP Service), versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker with administrator privileges to access u…

Mitigation only
Fix from $1,600 2020-04-14
Junos Os Evolved MEDIUM 5.5
CVE-2020-1620

A local, authenticated user with shell can obtain the hashed values of login passwords via configd streamer log. This issue affects all versions of J…

Fix: 19.3r1+
Fix from $1,600 2020-04-08
Junos Os Evolved MEDIUM 5.5
CVE-2020-1621

A local, authenticated user with shell can obtain the hashed values of login passwords via configd traces. This issue affects all versions of Junos O…

Fix: 19.3r1+
Fix from $1,600 2020-04-08
Junos Os Evolved MEDIUM 5.5
CVE-2020-1622

A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via the EvoSharedObjStore. This issue affec…

Fix: 19.1r1+
Fix from $1,600 2020-04-08
Junos Os Evolved MEDIUM 5.5
CVE-2020-1623

A local, authenticated user with shell can view sensitive configuration information via the ev.ops configuration file. This issue affects all version…

Fix: 19.2r1+
Fix from $1,600 2020-04-08
Junos Os Evolved MEDIUM 5.5
CVE-2020-1624

A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via raw objmon configuration files. This is…

Fix: 19.1r1+
Fix from $1,600 2020-04-08
Android HIGH 7.5
CVE-2020-11605

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. There is sensitive information exposure from dumpstate i…

Mitigation only
Fix from $1,950 2020-04-08
Plugin Publishing MEDIUM 6.5
CVE-2020-7599

All versions of com.gradle.plugin-publish before 0.11.0 are vulnerable to Insertion of Sensitive Information into Log File. When a plugin author publ…

Fix: 0.11.0+
Fix from $1,600 2020-03-30
Abusefilter HIGH 7.5
CVE-2019-16528

An issue was discovered in the AbuseFilter extension for MediaWiki. includes/special/SpecialAbuseLog.php allows attackers to obtain sensitive informa…

Patch available
Fix from $1,950 2020-03-20
Easybuild MEDIUM 5.5
CVE-2020-5262

In EasyBuild before version 4.1.2, the GitHub Personal Access Token (PAT) used by EasyBuild for the GitHub integration features (like `--new-pr`, `--…

Fix: 4.1.2+
Fix from $1,600 2020-03-19
Ansible Engine MEDIUM 5.5
CVE-2020-1753

A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2…

Fix: 2.7.18 / 2.8.11+
Fix from $1,600 2020-03-16
Xtremio Management Server MEDIUM 6.7
CVE-2019-18576

Dell EMC XtremIO XMS versions prior to 6.3.0 contain an information disclosure vulnerability where OS users’ passwords are logged in local files. Mal…

Fix: 6.3.0+
Fix from $1,600 2020-03-13
Fortiweb MEDIUM 6.5
CVE-2019-16157

An information exposure vulnerability in Fortinet FortiWeb 6.2.0 CLI and earlier may allow an authenticated user to view sensitive information being …

Fix: after 6.2.0
Fix from $1,600 2020-03-13
Xclarity Administrator MEDIUM 6.0
CVE-2019-19756

An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered Windows OS credentials, used to perform driver updates of manag…

Mitigation only
Fix from $1,600 2020-03-13