Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.2
CVE-2026-9073
A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication …
Satellite
Mitigation only
MEDIUM 6.5
CVE-2026-11820
A flaw was found in the community.general Ansible collection's nexmo module.
The module constructs HTTP requests to the Vonage/Nexmo SMS API by encod…
Enterprise Linux
Mitigation only
MEDIUM 5.5
CVE-2026-11819
Module: plugins/modules/keyring_info.py
CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Issue: The module retrieves a passphrase from …
Enterprise Linux
Mitigation only
MEDIUM 5.5
CVE-2025-14010
A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifica…
Community.general
Patch available
MEDIUM 6.3
CVE-2023-4380
A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. T…
Ansible Automation Platform
Mitigation only
MEDIUM 5.5
CVE-2021-3684
A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the…
Openshift Assisted Installer
1.0.25.3+
MEDIUM 5.5
CVE-2021-20180
A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using…
Ansible
2.9.18+
MEDIUM 5.5
CVE-2021-20191
A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when usi…
Ansible
1.2.2 / 1.3.2+
MEDIUM 5.5
CVE-2021-20178
A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using…
Ansible
2.9.18+
HIGH 8.8
CVE-2021-3528
A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator and the noobaa core are leake…
Noobaa Operator
5.7.0+
MEDIUM 5.5
CVE-2021-3447
A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on managed nod…
Ansible
1.2.2 / 3.8.2+
MEDIUM 5.3
CVE-2020-25640
A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inser…
Wildfly
21.0.0+
MEDIUM 5.5
CVE-2020-10762
An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes …
Gluster Block
0.5.1+
MEDIUM 5.5
CVE-2020-10763
An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access t…
Gluster Storage
10.1.0+
MEDIUM 5.5
CVE-2020-14330
An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json o…
Ansible Engine
2.9.12+
MEDIUM 5.5
CVE-2020-14332
A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive dat…
Ansible Engine
2.8.14 / 2.9.12+
HIGH 7.5
CVE-2020-10752
A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server pa…
Openshift Container Platform
Patch available
MEDIUM 5.5
CVE-2020-1698
A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highe…
Keycloak
9.0.0+
HIGH 8.2
CVE-2020-10712
A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry operator a…
Openshift Container Platform
after 4.1
MEDIUM 5.5
CVE-2020-1753
A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2…
Ansible Engine
2.7.18 / 2.8.11+
MEDIUM 6.5
CVE-2019-14854
OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or hig…
Openshift Container Platform
No fix yet
MEDIUM 6.5
CVE-2019-14864
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True w…
Ansible
2.7.15 / 2.8.7+
MEDIUM 5.5
CVE-2014-3536
CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration
Cloudforms Management Engine
Mitigation only
MEDIUM 6.5
CVE-2019-10213
OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set t…
Openshift Container Platform
Patch available
MEDIUM 5.5
CVE-2019-14858
A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters mar…
Ansible Engine
after 3.5.0
HIGH 7.8
CVE-2019-14846
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level whi…
Ansible Engine
2.6.20 / 2.7.14+
CRITICAL 9.8
CVE-2019-10212
A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to o…
Undertow
2.0.20+
MEDIUM 5.5
CVE-2019-10194
Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could b…
Virtualization Manager
Mitigation only
CRITICAL 9.8
CVE-2019-3888
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connector…
Undertow
2.0.21+
HIGH 7.8
CVE-2019-3891
It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin da…
Satellite
No fix yet