Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Connections MEDIUM 5.5
CVE-2020-4083

HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a local user.

Patch available
Fix from $1,600 2020-03-05
Capi Release MEDIUM 6.5
CVE-2020-5400

Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive in…

Fix: 1.91.0 / 12.33.0+
Fix from $1,600 2020-02-27
Nifi HIGH 7.5
CVE-2020-1942

In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the …

Fix: after 1.11.0
Fix from $1,950 2020-02-11
Fabric Operating System HIGH 7.5
CVE-2019-16203

Brocade Fabric OS Versions before v8.2.2a and v8.2.1d could expose the credentials of the remote ESRS server when these credentials are given as a co…

Fix: 8.2.1d / 8.2.2a+
Fix from $1,950 2020-02-05
Fabric Operating System HIGH 7.5
CVE-2019-16204

Brocade Fabric OS Versions before v7.4.2f, v8.2.2a, v8.1.2j and v8.2.1d could expose external passwords, common secrets or authentication keys used b…

Fix: 7.4.2f / 8.1.2j+
Fix from $1,950 2020-02-05
Stealth HIGH 7.5
CVE-2019-18193

In Unisys Stealth (core) 3.4.108.0, 3.4.209.x, 4.0.027.x and 4.0.114, key material inadvertently logged under certain conditions. Fixed included in 3…

Mitigation only
Fix from $1,950 2020-02-03
Nifi MEDIUM 5.3
CVE-2020-1928

An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purpose…

Mitigation only
Fix from $1,600 2020-01-28
Yast2 Rmt MEDIUM 5.5
CVE-2018-20105

A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers…

Fix: 1.2.2+
Fix from $1,600 2020-01-27
Simplesamlphp MEDIUM 5.4
CVE-2020-5225

Log injection in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script, which receives error reports and sends them via email to the sys…

Fix: 1.18.4+
Fix from $1,600 2020-01-24
Command Centre MEDIUM 5.5
CVE-2020-7215

An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 before 8.10.1134(MR4). External sy…

Fix: 7.80 / 7.90.991+
Fix from $1,600 2020-01-20
Operations Manager MEDIUM 6.5
CVE-2019-11292

Pivotal Ops Manager, versions 2.4.x prior to 2.4.27, 2.5.x prior to 2.5.24, 2.6.x prior to 2.6.16, and 2.7.x prior to 2.7.5, logs all query parameter…

Fix: 2.4.27 / 2.5.24+
Fix from $1,600 2020-01-09
Openshift Container Platform MEDIUM 6.5
CVE-2019-14854

OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or hig…

No fix yet
Fix from $1,600 2020-01-07
Ansible MEDIUM 6.5
CVE-2019-14864

Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True w…

Fix: 2.7.15 / 2.8.7+
Fix from $1,600 2020-01-02
Zxcloud Goldendata Vap MEDIUM 5.3
CVE-2019-3429

All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have a file reading vulnerability. Attackers could obtain log file information w…

Mitigation only
Fix from $1,600 2019-12-23
Webpanel MEDIUM 6.5
CVE-2019-14782

CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.856 through 0.9.8.864 allows an attacker to get a victim's session file name from the /tmp direc…

Fix: after 0.9.8.864
Fix from $1,600 2019-12-17
Webpanel MEDIUM 6.5
CVE-2019-15235

CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.864 allows an attacker to get a victim's session file name from /home/[USERNAME]/tmp/session/ses…

Fix: after 0.9.8.864
Fix from $1,600 2019-12-17
Cloudforms Management Engine MEDIUM 5.5
CVE-2014-3536

CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration

Mitigation only
Fix from $1,600 2019-12-15
Continuous Delivery MEDIUM 6.5
CVE-2019-10695

When using the cd4pe::root_configuration task to configure a Continuous Delivery for PE installation, the root user’s username and password were expo…

Fix: 1.2.1+
Fix from $1,600 2019-12-12
Cf Deployment MEDIUM 6.5
CVE-2019-11293

Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter…

Fix: 12.12.0 / 74.10.0+
Fix from $1,600 2019-12-06
Fedora MEDIUM 6.5
CVE-2019-10195

A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIP…

Fix: 4.6.7 / 4.7.4+
Fix from $1,600 2019-11-27
Cf Deployment HIGH 7.5
CVE-2019-11290

Cloud Foundry UAA Release, versions prior to v74.8.0, logs all query parameters to tomcat’s access file. If the query parameters are used to provide …

Fix: 12.10.0 / 74.8.0+
Fix from $1,950 2019-11-26
Openshift Container Platform MEDIUM 6.5
CVE-2019-10213

OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set t…

Patch available
Fix from $1,600 2019-11-25
Linux Kernel MEDIUM 5.5
CVE-2019-19039

__btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENOENT case, which allows local …

Fix: after 5.3.12
Fix from $1,600 2019-11-21
Big Ip Access Policy Manager MEDIUM 6.5
CVE-2019-6662

On BIG-IP 13.1.0-13.1.1.4, sensitive information is logged into the local log files and/or remote logging targets when restjavad processes an invalid…

Fix: 13.1.1.5+
Fix from $1,600 2019-11-15
Moodle HIGH 7.5
CVE-2012-1156

Moodle before 2.2.2 has users' private files included in course backups

Fix: 2.2.2+
Fix from $1,950 2019-11-14
Advanced Threat Defense MEDIUM 6.5
CVE-2019-3649

Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attackers to gain access to has…

Fix: 4.8+
Fix from $1,600 2019-11-13
Brocade Sannav MEDIUM 5.5
CVE-2019-16206

The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and the 'debug' logging level…

Fix: 2.0+
Fix from $1,600 2019-11-08
Brocade Sannav MEDIUM 5.5
CVE-2019-16210

Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save.

Fix: 2.0+
Fix from $1,600 2019-11-08
Monkey HIGH 7.5
CVE-2013-1771

The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo.

Mitigation only
Fix from $1,950 2019-11-07
Impala HIGH 7.5
CVE-2019-10084

In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions o…

Fix: after 3.2.0
Fix from $1,950 2019-11-05