Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
MEDIUM 6.5 CVE-2023-38067 In JetBrains TeamCity before 2023.05.1 build parameters of the "password" type could be written to the agent log Teamcity 2023.05.1+ Fix from $1,6002023-07-12 HIGH 7.5 CVE-2023-35695 A remote attacker could leverage a vulnerability in Trend Micro Mobile Security (Enterprise) 9.8 SP5 to download a particular log file which may cont… Mobile Security Patch available Fix from $1,9502023-06-26 MEDIUM 5.5 CVE-2023-32392 A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4… Ipados 9.5 / 11.7.7+ Fix from $1,6002023-06-23 MEDIUM 6.5 CVE-2023-20885 Vulnerability in Cloud Foundry Notifications, Cloud Foundry SMB-volume release, Cloud FOundry cf-nfs-volume release.This issue affects Notifications:… Cloud Foundry Nfs Volume 3.1.19 / 5.0.27+ Fix from $1,6002023-06-16 MEDIUM 6.5 CVE-2023-26207 An insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.2.0 through 7.2.4 and FortiProxy 7.0.0 through 7.0.10. 7.2.0 … Fortiproxy after 7.2.4 Fix from $1,6002023-06-13 MEDIUM 5.5 CVE-2023-2878 Kubernetes secrets-store-csi-driver in versions before 1.3.3 discloses service account tokens in logs. Secrets Store Csi Driver 1.3.3+ Fix from $1,6002023-06-07 HIGH 8.8 CVE-2023-34097 hoppscotch is an open source API development ecosystem. In versions prior to 2023.4.5 the database password is exposed in the logs when showing the d… Hoppscotch 2023.4.5+ Fix from $1,9502023-06-05 MEDIUM 5.3 CVE-2023-34223 In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases Teamcity 2023.05+ Fix from $1,6002023-05-31 MEDIUM 5.5 CVE-2022-0010 Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering Tools. An attacker, who al… Platform Engineering Tools after 6.1.0 Fix from $1,6002023-05-22 HIGH 7.5 CVE-2023-33001 Jenkins HashiCorp Vault Plugin 360.v0a_1c04cf807d and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log when… Hashicorp Vault after 360.v0a_1c04cf807d Fix from $1,9502023-05-16 HIGH 7.5 CVE-2023-2514 Mattermost Sever fails to redact the DB username and password before emitting an application log during server initialization.  Mattermost after 7.9.1 Fix from $1,9502023-05-12 MEDIUM 5.5 CVE-2023-31207 Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause the automation user's secret… Checkmk Mitigation only Fix from $1,6002023-05-02 MEDIUM 5.5 CVE-2023-1786 Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and poss… Cloud Init 23.1.2+ Fix from $1,6002023-04-26 MEDIUM 6.5 CVE-2023-31056 CloverDX before 5.17.3 writes passwords to the audit log in certain situations, if the audit log is enabled and single sign-on is not employed. The f… Cloverdx 5.17.3+ Fix from $1,6002023-04-24 MEDIUM 5.5 CVE-2021-3429 When instructing cloud-init to set a random password for a new user account, versions before 21.2 would write that password to the world-readable log… Cloud Init 21.2+ Fix from $1,6002023-04-19 MEDIUM 5.5 CVE-2022-2084 Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported. This leak could include h… Cloud Init 22.3+ Fix from $1,6002023-04-19 MEDIUM 5.5 CVE-2023-30610 aws-sigv4 is a rust library for low level request signing in the aws cloud platform. The `aws_sigv4::SigningParams` struct had a derived `Debug` impl… Aws Sigv4 Mitigation only Fix from $1,6002023-04-19 MEDIUM 6.3 CVE-2023-29002 Cilium is a networking, observability, and security solution with an eBPF-based dataplane. When run in debug mode, Cilium will log the contents of th… Cilium 1.11.16 / 1.12.9+ Fix from $1,6002023-04-18 MEDIUM 5.5 CVE-2022-48228 An issue was discovered in Acuant AsureID Sentinel before 5.2.149. It uses the root of the C: drive for the i-Dentify and Sentinel Installer log file… Acuant Asureid Sentinel 5.2.149+ Fix from $1,6002023-04-04 MEDIUM 6.5 CVE-2022-43772 Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Data Plugin expose the username a… Vantara Pentaho Business Analytics Server 9.3.0.1+ Fix from $1,6002023-04-03 MEDIUM 5.5 CVE-2023-1550 Insertion of Sensitive Information into log file vulnerability in NGINX Agent. NGINX Agent version 2.0 before 2.23.3 inserts sensitive information in… Nginx Agent 2.9.0 / 2.23.3+ Fix from $1,6002023-03-29 MEDIUM 6.5 CVE-2023-25721 Veracode Scan Jenkins Plugin before 23.3.19.0, when the "Connect using proxy" option is enabled and configured with proxy credentials and when the Je… Veracode 23.3.19.0+ Fix from $1,6002023-03-28 MEDIUM 5.5 CVE-2021-3684 A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the… Openshift Assisted Installer 1.0.25.3+ Fix from $1,6002023-03-24 HIGH 7.5 CVE-2023-28441 smartCARS 3 is flight tracking software. In version 0.5.8 and prior, all persons who have failed login attempts will have their password stored in er… Smartcars 3 0.5.9+ Fix from $1,9502023-03-24 MEDIUM 5.5 CVE-2023-28443 Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 9.23.3, the `directus_refresh_token` is not redacte… Directus 9.23.3+ Fix from $1,6002023-03-24 MEDIUM 5.5 CVE-2023-20859 In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sen… Spring Cloud Config 2.3.3 / 3.0.2+ Fix from $1,6002023-03-23 MEDIUM 5.5 CVE-2023-22481 FreshRSS is a self-hosted RSS feed aggregator. When using the greader API, the provided password is logged in clear in `users/_/log_api.txt` in the c… Freshrss 1.21.0+ Fix from $1,6002023-03-06 MEDIUM 5.5 CVE-2022-43923 IBM Maximo Application Suite 8.8.0 and 8.9.0 stores potentially sensitive information that could be read by a local user. IBM X-Force ID: 241584. Maximo Application Suite Mitigation only Fix from $1,6002023-02-24 MEDIUM 6.5 CVE-2023-0815 Potential Insertion of Sensitive Information into Jetty Log Files in multiple versions of OpenNMS Meridian and Horizon could allow disclosure of user… Horizon 31.0.4 / 2023.1.0+ Fix from $1,6002023-02-23 MEDIUM 6.5 CVE-2022-43870 IBM Spectrum Virtualize 8.3, 8.4, and 8.5 could disclose SNMPv3 server credentials to an authenticated user in log files. IBM X-Force ID: 239540. Spectrum Virtualize Mitigation only Fix from $1,6002023-02-22