Vulnerability index

Browse CVEs

32 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
MEDIUM 6.5 CVE-2026-68969 Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoint… Airflow 3.3.1+ Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-65945 Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. Ranger No fix yet Fix from $4,0002026-08-10 MEDIUM 6.5 CVE-2026-43826 The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:[email protected]:920… Apache Airflow Providers Opensearch 1.9.1+ Fix from $1,6002026-05-11 MEDIUM 6.5 CVE-2026-41018 The Elasticsearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:[email protected]:… Apache Airflow Providers Elasticsearch 6.5.3+ Fix from $1,6002026-05-11 HIGH 7.5 CVE-2026-31987 JWT Tokens used by tasks were exposed in logs. This could allow UI users to act as Dag Authors. Users are advised to upgrade to Airflow version that… Airflow 3.2.0+ Fix from $1,9502026-04-16 HIGH 7.5 CVE-2025-66236 Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to … Airflow 3.2.0+ Fix from $1,9502026-04-13 HIGH 7.5 CVE-2026-34487 Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernet… Tomcat 9.0.117 / 10.1.54+ Fix from $1,9502026-04-09 MEDIUM 5.5 CVE-2026-27315 Sensitive Information Leak in cqlsh in Apache Cassandra 4.0 allows access to sensitive information, like passwords, from previously executed cqlsh co… Cassandra 4.0.20+ Fix from $1,6002026-04-07 HIGH 7.5 CVE-2026-24308 Improper handling of configuration values in ZKConfig in Apache ZooKeeper 3.8.5 and 3.9.4 on all platforms allows an attacker to expose sensitive inf… Zookeeper 3.8.6 / 3.9.5+ Fix from $1,9502026-03-07 MEDIUM 6.5 CVE-2025-27555 Airflow versions before 2.11.1 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which… Airflow 2.11.1+ Fix from $1,6002026-02-24 MEDIUM 6.5 CVE-2025-59355 A vulnerability. When org.apache.linkis.metadata.util.HiveUtils.decode() fails to perform Base64 decoding, it records the complete input parameter s… Linkis 1.8.0+ Fix from $1,6002026-01-19 HIGH 7.5 CVE-2025-68675 In Apache Airflow versions before 3.1.6, and 2.11.1 the proxies and proxy fields within a Connection may include proxy URLs containing embedded authe… Airflow 3.1.6+ Fix from $1,9502026-01-16 HIGH 7.5 CVE-2025-62232 Sensitive data exposure via logging in basic-auth leads to plaintext usernames and passwords written to error logs and forwarded to log sinks when lo… Apisix 3.14.0+ Fix from $1,9502025-10-31 HIGH 7.5 CVE-2025-26864 Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in the OpenIdAuthorizer of… Iotdb 1.3.4+ Fix from $1,9502025-05-14 HIGH 7.5 CVE-2025-26795 Exposure of Sensitive Information to an Unauthorized Actor, Insertion of Sensitive Information into Log File vulnerability in Apache IoTDB JDBC drive… Iotdb 1.3.4 / 2.0.2+ Fix from $1,9502025-05-14 MEDIUM 6.5 CVE-2025-27391 Insertion of Sensitive Information into Log File vulnerability in Apache ActiveMQ Artemis. All the values of the broker properties are logged when th… Artemis 2.40.0+ Fix from $1,6002025-04-09 MEDIUM 6.5 CVE-2025-30677 Apache Pulsar contains multiple connectors for integrating with Apache Kafka. The Pulsar IO Apache Kafka Source Connector, Sink Connector, and Kafka … Pulsar 3.0.11 / 3.3.6+ Fix from $1,6002025-04-09 HIGH 7.5 CVE-2024-41178 Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (`object_store` crate), version 0.10.1 and earlier on all platforms using… Arrow after 0.10.1 Fix from $1,9502024-07-23 MEDIUM 6.5 CVE-2024-31391 Insertion of Sensitive Information into Log File vulnerability in the Apache Solr Operator. This issue affects all versions of the Apache Solr Opera… Solr Operator 0.8.1+ Fix from $1,6002024-04-12 MEDIUM 5.3 CVE-2023-50740 In Apache Linkis <=1.4.0, The password is printed to the log when using the Oracle data source of the Linkis data source module.  We recommend users … Linkis 1.5.0+ Fix from $1,6002024-03-06 MEDIUM 6.5 CVE-2023-51702 Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes th… Airflow 2.6.1 / 7.0.0+ Fix from $1,6002024-01-24 HIGH 7.5 CVE-2023-46215 Insertion of Sensitive Information into Log File vulnerability in Apache Airflow Celery provider, Apache Airflow. Sensitive information logged as cl… Airflow 2.7.0+ Fix from $1,9502023-10-28 MEDIUM 6.5 CVE-2023-44483 All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue whe… Santuario Xml Security For Java 2.2.6 / 2.3.4+ Fix from $1,6002023-10-20 HIGH 7.5 CVE-2021-34797 Apache Geode versions up to 1.12.4 and 1.13.4 are vulnerable to a log file redaction of sensitive information flaw when using values that begin with … Geode after 1.13.4 Fix from $1,9502022-01-04 HIGH 7.5 CVE-2021-28131 Impala sessions use a 16 byte secret to verify that the session is not being hijacked by another user. However, these secrets appear in the Impala lo… Impala 4.0.0+ Fix from $1,9502021-07-22 HIGH 7.5 CVE-2020-9486 In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values. When a flow was tr… Nifi after 1.11.4 Fix from $1,9502020-10-01 HIGH 7.5 CVE-2020-1942 In Apache NiFi 0.0.1 to 1.11.0, the flow fingerprint factory generated flow fingerprints which included sensitive property descriptor values. In the … Nifi after 1.11.0 Fix from $1,9502020-02-11 MEDIUM 5.3 CVE-2020-1928 An information disclosure vulnerability was found in Apache NiFi 1.10.0. The sensitive parameter parser would log parsed values for debugging purpose… Nifi Mitigation only Fix from $1,6002020-01-28 HIGH 7.5 CVE-2019-10084 In Apache Impala 2.7.0 to 3.2.0, an authenticated user with access to the IDs of active Impala queries or sessions can interact with those sessions o… Impala after 3.2.0 Fix from $1,9502019-11-05 HIGH 7.5 CVE-2019-0202 The Apache Storm Logviewer daemon exposes HTTP-accessible endpoints to read/search log files on hosts running Storm. In Apache Storm versions 0.9.1-i… Storm after 1.2.2 Fix from $1,9502019-07-26