Vulnerability index

Browse CVEs

40 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Sensitive Information in LogsCWE-532 × clear
MEDIUM 6.2 CVE-2026-9073 A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication … Satellite Mitigation only Fix from $1,6002026-06-23 MEDIUM 6.5 CVE-2026-11820 A flaw was found in the community.general Ansible collection's nexmo module. The module constructs HTTP requests to the Vonage/Nexmo SMS API by encod… Enterprise Linux Mitigation only Fix from $1,6002026-06-23 MEDIUM 5.5 CVE-2026-11819 Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module retrieves a passphrase from … Enterprise Linux Mitigation only Fix from $1,6002026-06-23 MEDIUM 5.5 CVE-2025-14010 A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sensitive credentials, specifica… Community.general Patch available Fix from $1,6002025-12-04 MEDIUM 6.3 CVE-2023-4380 A logic flaw exists in Ansible Automation platform. Whenever a private project is created with incorrect credentials, they are logged in plaintext. T… Ansible Automation Platform Mitigation only Fix from $1,6002023-10-04 MEDIUM 5.5 CVE-2021-3684 A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the… Openshift Assisted Installer 1.0.25.3+ Fix from $1,6002023-03-24 MEDIUM 5.5 CVE-2021-20180 A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using… Ansible 2.9.18+ Fix from $1,6002022-03-16 MEDIUM 5.5 CVE-2021-20191 A flaw was found in ansible. Credentials, such as secrets, are being disclosed in console log by default and not protected by no_log feature when usi… Ansible 1.2.2 / 1.3.2+ Fix from $1,6002021-05-26 MEDIUM 5.5 CVE-2021-20178 A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using… Ansible 2.9.18+ Fix from $1,6002021-05-26 HIGH 8.8 CVE-2021-3528 A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator and the noobaa core are leake… Noobaa Operator 5.7.0+ Fix from $1,9502021-05-13 MEDIUM 5.5 CVE-2021-3447 A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on managed nod… Ansible 1.2.2 / 3.8.2+ Fix from $1,6002021-04-01 MEDIUM 5.3 CVE-2020-25640 A flaw was discovered in WildFly before 21.0.0.Final where, Resource adapter logs plain text JMS password at warning level on connection error, inser… Wildfly 21.0.0+ Fix from $1,6002020-11-24 MEDIUM 5.5 CVE-2020-10762 An information-disclosure flaw was found in the way that gluster-block before 0.5.1 logs the output from gluster-block CLI operations. This includes … Gluster Block 0.5.1+ Fix from $1,6002020-11-24 MEDIUM 5.5 CVE-2020-10763 An information-disclosure flaw was found in the way Heketi before 10.1.0 logs sensitive information. This flaw allows an attacker with local access t… Gluster Storage 10.1.0+ Fix from $1,6002020-11-24 MEDIUM 5.5 CVE-2020-14330 An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json o… Ansible Engine 2.9.12+ Fix from $1,6002020-09-11 MEDIUM 5.5 CVE-2020-14332 A flaw was found in the Ansible Engine when using module_args. Tasks executed with check mode (--check-mode) do not properly neutralize sensitive dat… Ansible Engine 2.8.14 / 2.9.12+ Fix from $1,6002020-09-11 HIGH 7.5 CVE-2020-10752 A flaw was found in the OpenShift API Server, where it failed to sufficiently protect OAuthTokens by leaking them into the logs when an API Server pa… Openshift Container Platform Patch available Fix from $1,9502020-06-12 MEDIUM 5.5 CVE-2020-1698 A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highe… Keycloak 9.0.0+ Fix from $1,6002020-05-11 HIGH 8.2 CVE-2020-10712 A flaw was found in OpenShift Container Platform version 4.1 and later. Sensitive information was found to be logged by the image registry operator a… Openshift Container Platform after 4.1 Fix from $1,9502020-04-22 MEDIUM 5.5 CVE-2020-1753 A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2… Ansible Engine 2.7.18 / 2.8.11+ Fix from $1,6002020-03-16 MEDIUM 6.5 CVE-2019-14854 OpenShift Container Platform 4 does not sanitize secret data written to static pod logs when the log level in a given operator is set to Debug or hig… Openshift Container Platform No fix yet Fix from $1,6002020-01-07 MEDIUM 6.5 CVE-2019-14864 Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_log set it to True w… Ansible 2.7.15 / 2.8.7+ Fix from $1,6002020-01-02 MEDIUM 5.5 CVE-2014-3536 CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration Cloudforms Management Engine Mitigation only Fix from $1,6002019-12-15 MEDIUM 6.5 CVE-2019-10213 OpenShift Container Platform, versions 4.1 and 4.2, does not sanitize secret data written to pod logs when the log level in a given operator is set t… Openshift Container Platform Patch available Fix from $1,6002019-11-25 MEDIUM 5.5 CVE-2019-14858 A vulnerability was found in Ansible engine 2.x up to 2.8 and Ansible tower 3.x up to 3.5. When a module has an argument_spec with sub parameters mar… Ansible Engine after 3.5.0 Fix from $1,6002019-10-14 HIGH 7.8 CVE-2019-14846 In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at the DEBUG level whi… Ansible Engine 2.6.20 / 2.7.14+ Fix from $1,9502019-10-08 CRITICAL 9.8 CVE-2019-10212 A flaw was found in, all under 2.0.20, in the Undertow DEBUG log for io.undertow.request.security. If enabled, an attacker could abuse this flaw to o… Undertow 2.0.20+ Fix from $2,3002019-10-02 MEDIUM 5.5 CVE-2019-10194 Sensitive passwords used in deployment and configuration of oVirt Metrics, all versions. were found to be insufficiently protected. Passwords could b… Virtualization Manager Mitigation only Fix from $1,6002019-07-11 CRITICAL 9.8 CVE-2019-3888 A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connector… Undertow 2.0.21+ Fix from $2,3002019-06-12 HIGH 7.8 CVE-2019-3891 It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin da… Satellite No fix yet Fix from $1,9502019-04-15