Vulnerability index

Browse CVEs

912 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
MEDIUM 5.5 CVE-2020-4083 HCL Connections 6.5 is vulnerable to possible information leakage. Connections could disclose sensitive information via trace logs to a local user. Connections Patch available Fix from $1,6002020-03-05 MEDIUM 6.5 CVE-2020-5400 Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive in… Capi Release 1.91.0 / 12.33.0+ Fix from $1,6002020-02-27 HIGH 7.5 CVE-2020-1942 In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the … Nifi after 1.11.0 Fix from $1,9502020-02-11 HIGH 7.5 CVE-2019-16203 Brocade Fabric OS Versions before v8.2.2a and v8.2.1d could expose the credentials of the remote ESRS server when these credentials are given as a co… Fabric Operating System 8.2.1d / 8.2.2a+ Fix from $1,9502020-02-05 HIGH 7.5 CVE-2019-16204 Brocade Fabric OS Versions before v7.4.2f, v8.2.2a, v8.1.2j and v8.2.1d could expose external passwords, common secrets or authentication keys used b… Fabric Operating System 7.4.2f / 8.1.2j+ Fix from $1,9502020-02-05 HIGH 7.5 CVE-2019-18193 In Unisys Stealth (core) 3.4.108.0, 3.4.209.x, 4.0.027.x and 4.0.114, key material inadvertently logged under certain conditions. Fixed included in 3… Stealth Mitigation only Fix from $1,9502020-02-03 MEDIUM 5.3 CVE-2020-1928 An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purpose… Nifi Mitigation only Fix from $1,6002020-01-28 MEDIUM 5.5 CVE-2018-20105 A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers… Yast2 Rmt 1.2.2+ Fix from $1,6002020-01-27 MEDIUM 5.4 CVE-2020-5225 Log injection in SimpleSAMLphp before version 1.18.4. The www/erroreport.php script, which receives error reports and sends them via email to the sys… Simplesamlphp 1.18.4+ Fix from $1,6002020-01-24 MEDIUM 5.5 CVE-2020-7215 An issue was discovered in Gallagher Command Centre 7.x before 7.90.991(MR5), 8.00 before 8.00.1161(MR5), and 8.10 before 8.10.1134(MR4). External sy… Command Centre 7.80 / 7.90.991+ Fix from $1,6002020-01-20 MEDIUM 6.5 CVE-2019-11292 Pivotal Ops Manager, versions 2.4.x prior to 2.4.27, 2.5.x prior to 2.5.24, 2.6.x prior to 2.6.16, and 2.7.x prior to 2.7.5, logs all query parameter… Operations Manager 2.4.27 / 2.5.24+ Fix from $1,6002020-01-09 MEDIUM 6.5 CVE-2019-14854 OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or hig… Openshift Container Platform No fix yet Fix from $1,6002020-01-07 MEDIUM 6.5 CVE-2019-14864 Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True w… Ansible 2.7.15 / 2.8.7+ Fix from $1,6002020-01-02 MEDIUM 5.3 CVE-2019-3429 All versions up to V4.01.01.02 of ZTE ZXCLOUD GoldenData VAP product have a file reading vulnerability. Attackers could obtain log file information w… Zxcloud Goldendata Vap Mitigation only Fix from $1,6002019-12-23 MEDIUM 6.5 CVE-2019-14782 CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.856 through 0.9.8.864 allows an attacker to get a victim's session file name from the /tmp direc… Webpanel after 0.9.8.864 Fix from $1,6002019-12-17 MEDIUM 6.5 CVE-2019-15235 CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.864 allows an attacker to get a victim's session file name from /home/[USERNAME]/tmp/session/ses… Webpanel after 0.9.8.864 Fix from $1,6002019-12-17 MEDIUM 5.5 CVE-2014-3536 CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration Cloudforms Management Engine Mitigation only Fix from $1,6002019-12-15 MEDIUM 6.5 CVE-2019-10695 When using the cd4pe::root_configuration task to configure a Continuous Delivery for PE installation, the root user’s username and password were expo… Continuous Delivery 1.2.1+ Fix from $1,6002019-12-12 MEDIUM 6.5 CVE-2019-11293 Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter… Cf Deployment 12.12.0 / 74.10.0+ Fix from $1,6002019-12-06 MEDIUM 6.5 CVE-2019-10195 A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIP… Fedora 4.6.7 / 4.7.4+ Fix from $1,6002019-11-27 HIGH 7.5 CVE-2019-11290 Cloud Foundry UAA Release, versions prior to v74.8.0, logs all query parameters to tomcat’s access file. If the query parameters are used to provide … Cf Deployment 12.10.0 / 74.8.0+ Fix from $1,9502019-11-26 MEDIUM 6.5 CVE-2019-10213 OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set t… Openshift Container Platform Patch available Fix from $1,6002019-11-25 MEDIUM 5.5 CVE-2019-19039 __btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENOENT case, which allows local … Linux Kernel after 5.3.12 Fix from $1,6002019-11-21 MEDIUM 6.5 CVE-2019-6662 On BIG-IP 13.1.0-13.1.1.4, sensitive information is logged into the local log files and/or remote logging targets when restjavad processes an invalid… Big Ip Access Policy Manager 13.1.1.5+ Fix from $1,6002019-11-15 HIGH 7.5 CVE-2012-1156 Moodle before 2.2.2 has users' private files included in course backups Moodle 2.2.2+ Fix from $1,9502019-11-14 MEDIUM 6.5 CVE-2019-3649 Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attackers to gain access to has… Advanced Threat Defense 4.8+ Fix from $1,6002019-11-13 MEDIUM 5.5 CVE-2019-16206 The authentication mechanism, in Brocade SANnav versions before v2.0, logs plaintext account credentials at the ‘trace’ and the 'debug' logging level… Brocade Sannav 2.0+ Fix from $1,6002019-11-08 MEDIUM 5.5 CVE-2019-16210 Brocade SANnav versions before v2.0, logs plain text database connection password while triggering support save. Brocade Sannav 2.0+ Fix from $1,6002019-11-08 HIGH 7.5 CVE-2013-1771 The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo. Monkey Mitigation only Fix from $1,9502019-11-07 HIGH 7.5 CVE-2019-10084 In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions o… Impala after 3.2.0 Fix from $1,9502019-11-05