Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2021-06-04 CVE-2021-33839 Information Exposure vulnerability in Luca-App Luca
Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because the QR code of a Public Location can be intentionally confused with the QR code of a Private Meeting.
network
low complexity
luca-app CWE-200
7.5
2021-06-02 CVE-2017-8761 Information Exposure vulnerability in Openstack Swift
In OpenStack Swift through 2.10.1, 2.11.0 through 2.13.0, and 2.14.0, the proxy-server logs full tempurl paths, potentially leaking reusable tempurl signatures to anyone with read access to these logs.
network
low complexity
openstack CWE-200
4.3
2021-06-02 CVE-2020-14371 Information Exposure vulnerability in Redhat Satellite 6.0
A credential leak vulnerability was found in Red Hat Satellite.
network
low complexity
redhat CWE-200
6.5
2021-06-02 CVE-2020-14335 Information Exposure vulnerability in Redhat Satellite 6.0
A flaw was found in Red Hat Satellite, which allows a privileged attacker to read OMAPI secrets through the ISC DHCP of Smart-Proxy.
local
low complexity
redhat CWE-200
5.5
2021-06-01 CVE-2021-20585 Information Exposure vulnerability in IBM Security Verify Access 20.07
IBM Security Verify Access 20.07 could disclose sensitive information in HTTP server headers that could be used in further attacks against the system.
network
low complexity
ibm CWE-200
5.3
2021-05-27 CVE-2020-14329 Information Exposure vulnerability in Redhat Ansible Tower
A data exposure flaw was found in Ansible Tower in versions before 3.7.2, where sensitive data can be exposed from the /api/v2/labels/ endpoint.
local
low complexity
redhat CWE-200
3.3
2021-05-26 CVE-2021-22739 Information Exposure vulnerability in Schneider-Electric Homelynk Firmware and Spacelynk Firmware
Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause a device to be compromised when it is first configured.
network
high complexity
schneider-electric CWE-200
5.9
2021-05-26 CVE-2021-22740 Information Exposure vulnerability in Schneider-Electric Homelynk Firmware and Spacelynk Firmware
Information Exposure vulnerability exists in homeLYnk (Wiser For KNX) and spaceLYnk V2.60 and prior which could cause information to be exposed when an unauthorized file is uploaded.
network
low complexity
schneider-electric CWE-200
6.5
2021-05-25 CVE-2021-23937 Information Exposure vulnerability in Apache Wicket
A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trigger arbitrary DNS lookups from the server when the X-Forwarded-For header is not properly sanitized.
network
low complexity
apache CWE-200
7.5
2021-05-25 CVE-2021-32638 Information Exposure vulnerability in Github Codeql Action
Github's CodeQL action is provided to run CodeQL-based code scanning on non-GitHub CI/CD systems and requires a GitHub access token to connect to a GitHub repository.
local
low complexity
github CWE-200
4.4