Vulnerability index

Browse CVEs

909 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
MEDIUM 6.5 CVE-2023-46675 An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error or in the event where debug … Kibana 7.17.16 / 8.11.2+ Fix from $1,6002023-12-13 MEDIUM 6.5 CVE-2023-46671 An issue was discovered by Elastic whereby sensitive information may be recorded in Kibana logs in the event of an error. Elastic has released Kibana… Kibana 8.11.1+ Fix from $1,6002023-12-13 MEDIUM 6.5 CVE-2023-49922 An issue was discovered by Elastic whereby Beats and Elastic Agent would log a raw event in its own logs at the WARN or ERROR level if ingesting that… Elastic Beats 7.17.16 / 8.11.3+ Fix from $1,6002023-12-12 MEDIUM 6.5 CVE-2023-6687 An issue was discovered by Elastic whereby Elastic Agent would log a raw event in its own logs at the WARN or ERROR level if ingesting that event to … Elastic Agent 7.17.16 / 8.11.3+ Fix from $1,6002023-12-12 MEDIUM 6.5 CVE-2023-49923 An issue was discovered by Elastic whereby the Documents API of App Search logged the raw contents of indexed documents at INFO log level. Depending … Enterprise Search 7.17.16 / 8.11.2+ Fix from $1,6002023-12-12 CRITICAL 9.1 CVE-2023-36649 Insertion of sensitive information in the centralized (Grafana) logging system in ProLion CryptoSpike 3.0.15P2 allows remote attackers to impersonate… Cryptospike No fix yet Fix from $2,3002023-12-12 MEDIUM 5.5 CVE-2023-6460 A potential logging of the firestore key via logging within nodejs-firestore exists - Developers who were logging objects through this._settings woul… Cloud Firestore 6.1.0+ Fix from $1,6002023-12-04 MEDIUM 5.5 CVE-2023-6287 Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.8 allows local attacker to retrieve passwords via reading log files. Checkmk Appliance Firmware 1.6.8+ Fix from $1,6002023-11-27 MEDIUM 6.5 CVE-2023-48708 CodeIgniter Shield is an authentication and authorization provider for CodeIgniter 4. In affected versions successful login attempts are recorded wit… Shield Patch available Fix from $1,6002023-11-24 CRITICAL 9.8 CVE-2023-4677 Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs… Pandora Fms 773+ Fix from $2,3002023-11-23 MEDIUM 5.5 CVE-2023-25682 IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.1 stores potentially sensitive information in log file… Sterling B2b Integrator 6.0.3.9 / 6.1.2.3+ Fix from $1,6002023-11-22 MEDIUM 5.5 CVE-2023-46672 An issue was identified by Elastic whereby sensitive information is recorded in Logstash logs under specific circumstances. The prerequisites for th… Logstash 8.11.1+ Fix from $1,6002023-11-15 MEDIUM 5.5 CVE-2023-32283 Insertion of sensitive information into log file in some Intel(R) On Demand software before versions 1.16.2, 2.1.1, 3.1.0 may allow an authenticated … On Demand Mitigation only Fix from $1,6002023-11-14 MEDIUM 5.5 CVE-2022-46647 Insertion of sensitive information into log file for some Intel Unison software may allow an authenticated user to potentially enable information dis… Unison Software 20.14.2.3053 / 20.14.4244+ Fix from $1,6002023-11-14 HIGH 7.5 CVE-2023-47390 Headscale through 0.22.3 writes bearer tokens to info-level logs. Headscale after 0.22.3 Fix from $1,9502023-11-11 HIGH 7.5 CVE-2023-0436 The affected versions of MongoDB Atlas Kubernetes Operator may print sensitive information like GCP service account keys and API integration secrets … Atlas Kubernetes Operator 1.7.1+ Fix from $1,9502023-11-07 MEDIUM 6.5 CVE-2023-46255 SpiceDB is an open source, Google Zanzibar-inspired database for creating and managing security-critical application permissions. Prior to version 1.… Spicedb 1.27.0+ Fix from $1,6002023-10-31 HIGH 7.5 CVE-2023-46215 Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow. Sensitive information logged as cl… Airflow 2.7.0+ Fix from $1,9502023-10-28 HIGH 7.5 CVE-2023-31422 An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error. The issue impacts only Kibana v… Kibana Mitigation only Fix from $1,9502023-10-26 HIGH 8.1 CVE-2023-46667 An issue was discovered in Fleet Server >= v8.10.0 and < v8.10.3 where Agent enrolment tokens are being inserted into the Fleet Server’s log file in … Fleet Server 8.10.3+ Fix from $1,9502023-10-26 CRITICAL 9.1 CVE-2023-46668 If Elastic Endpoint (v7.9.0 - v8.10.3) is configured to use a non-default option in which the logging level is explicitly set to debug, and when Elas… Endpoint after 8.10.3 Fix from $2,3002023-10-26 MEDIUM 5.5 CVE-2023-41254 A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.1 and iPadOS 17.1, watchOS 10.1, iO… Ipados 10.1 / 13.6.1+ Fix from $1,6002023-10-25 MEDIUM 6.5 CVE-2023-44483 All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue whe… Santuario Xml Security For Java 2.2.6 / 2.3.4+ Fix from $1,6002023-10-20 MEDIUM 5.5 CVE-2023-45825 ydb-go-sdk is a pure Go native and database/sql driver for the YDB platform. Since ydb-go-sdk v3.48.6 if you use a custom credentials object (impleme… Ydb Go Sdk 3.53.2+ Fix from $1,6002023-10-19 MEDIUM 5.5 CVE-2023-5339 Mattermost Desktop fails to set an appropriate log level during initial run after fresh installation resulting in logging all keystrokes including pa… Mattermost Desktop after 5.4.0 Fix from $1,6002023-10-17 MEDIUM 5.5 CVE-2023-25604 An insertion of sensitive information into log file vulnerability in Fortinet FortiGuest 1.0.0 allows a local attacker to access plaintext passwords … Fortiguest Mitigation only Fix from $1,6002023-10-10 HIGH 7.5 CVE-2023-5499 Information exposure vulnerability in Shenzhen Reachfar v28, the exploitation of which could allow a remote attacker to retrieve all the week's logs … Reachfar Gps Firmware Mitigation only Fix from $1,9502023-10-10 MEDIUM 5.5 CVE-2023-41253 When on BIG-IP DNS or BIG-IP LTM enabled with DNS Services License, and a TSIG key is created, it is logged in plaintext in the audit log.  Note: Sof… Big Ip Domain Name System 15.1.9 / 16.1.4+ Fix from $1,6002023-10-10 MEDIUM 5.5 CVE-2023-43485 When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log.  Note: Software version… Big Iq Centralized Management 8.2.0.1.0.13.97-eng / 8.3.0.0.12.118-eng+ Fix from $1,6002023-10-10 MEDIUM 5.5 CVE-2023-5182 Sensitive data could be exposed in logs of subiquity version 23.09.1 and earlier. An attacker in the adm group could use this information to find has… Subiquity after 23.09.1 Fix from $1,6002023-10-07