Vulnerability index

Browse CVEs

40 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
Satellite MEDIUM 6.2
CVE-2026-9073

A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication …

Mitigation only
Fix from $1,600 2026-06-23
Enterprise Linux MEDIUM 6.5
CVE-2026-11820

A flaw was found in the community.general Ansible collection's nexmo module. The module constructs HTTP requests to the Vonage/Nexmo SMS API by encod…

Mitigation only
Fix from $1,600 2026-06-23
Enterprise Linux MEDIUM 5.5
CVE-2026-11819

Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module retrieves a passphrase from …

Mitigation only
Fix from $1,600 2026-06-23
Community.general MEDIUM 5.5
CVE-2025-14010

A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifica…

Patch available
Fix from $1,600 2025-12-04
Ansible Automation Platform MEDIUM 6.3
CVE-2023-4380

A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. T…

Mitigation only
Fix from $1,600 2023-10-04
Openshift Assisted Installer MEDIUM 5.5
CVE-2021-3684

A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the…

Fix: 1.0.25.3+
Fix from $1,600 2023-03-24
Ansible MEDIUM 5.5
CVE-2021-20180

A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using…

Fix: 2.9.18+
Fix from $1,600 2022-03-16
Ansible MEDIUM 5.5
CVE-2021-20191

A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when usi…

Fix: 1.2.2 / 1.3.2+
Fix from $1,600 2021-05-26
Ansible MEDIUM 5.5
CVE-2021-20178

A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using…

Fix: 2.9.18+
Fix from $1,600 2021-05-26
Noobaa Operator HIGH 8.8
CVE-2021-3528

A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator and the noobaa core are leake…

Fix: 5.7.0+
Fix from $1,950 2021-05-13
Ansible MEDIUM 5.5
CVE-2021-3447

A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on managed nod…

Fix: 1.2.2 / 3.8.2+
Fix from $1,600 2021-04-01
Wildfly MEDIUM 5.3
CVE-2020-25640

A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inser…

Fix: 21.0.0+
Fix from $1,600 2020-11-24
Gluster Block MEDIUM 5.5
CVE-2020-10762

An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes …

Fix: 0.5.1+
Fix from $1,600 2020-11-24
Gluster Storage MEDIUM 5.5
CVE-2020-10763

An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access t…

Fix: 10.1.0+
Fix from $1,600 2020-11-24
Ansible Engine MEDIUM 5.5
CVE-2020-14330

An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json o…

Fix: 2.9.12+
Fix from $1,600 2020-09-11
Ansible Engine MEDIUM 5.5
CVE-2020-14332

A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive dat…

Fix: 2.8.14 / 2.9.12+
Fix from $1,600 2020-09-11
Openshift Container Platform HIGH 7.5
CVE-2020-10752

A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server pa…

Patch available
Fix from $1,950 2020-06-12
Keycloak MEDIUM 5.5
CVE-2020-1698

A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highe…

Fix: 9.0.0+
Fix from $1,600 2020-05-11
Openshift Container Platform HIGH 8.2
CVE-2020-10712

A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry operator a…

Fix: after 4.1
Fix from $1,950 2020-04-22
Ansible Engine MEDIUM 5.5
CVE-2020-1753

A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2…

Fix: 2.7.18 / 2.8.11+
Fix from $1,600 2020-03-16
Openshift Container Platform MEDIUM 6.5
CVE-2019-14854

OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or hig…

No fix yet
Fix from $1,600 2020-01-07
Ansible MEDIUM 6.5
CVE-2019-14864

Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True w…

Fix: 2.7.15 / 2.8.7+
Fix from $1,600 2020-01-02
Cloudforms Management Engine MEDIUM 5.5
CVE-2014-3536

CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration

Mitigation only
Fix from $1,600 2019-12-15
Openshift Container Platform MEDIUM 6.5
CVE-2019-10213

OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set t…

Patch available
Fix from $1,600 2019-11-25
Ansible Engine MEDIUM 5.5
CVE-2019-14858

A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters mar…

Fix: after 3.5.0
Fix from $1,600 2019-10-14
Ansible Engine HIGH 7.8
CVE-2019-14846

In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level whi…

Fix: 2.6.20 / 2.7.14+
Fix from $1,950 2019-10-08
Undertow CRITICAL 9.8
CVE-2019-10212

A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to o…

Fix: 2.0.20+
Fix from $2,300 2019-10-02
Virtualization Manager MEDIUM 5.5
CVE-2019-10194

Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could b…

Mitigation only
Fix from $1,600 2019-07-11
Undertow CRITICAL 9.8
CVE-2019-3888

A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connector…

Fix: 2.0.21+
Fix from $2,300 2019-06-12
Satellite HIGH 7.8
CVE-2019-3891

It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin da…

No fix yet
Fix from $1,950 2019-04-15