Vulnerabilities > Information Exposure Through Log Files

DATE CVE VULNERABILITY TITLE RISK
2023-08-11 CVE-2023-4108 Information Exposure Through Log Files vulnerability in Mattermost
Mattermost fails to sanitize post metadata during audit logging resulting in permalinks contents being logged
network
low complexity
mattermost CWE-532
7.5
2023-08-02 CVE-2023-36494 Information Exposure Through Log Files vulnerability in F5 F5Os-A 1.4.0
Audit logs on F5OS-A may contain undisclosed sensitive information.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
local
low complexity
f5 CWE-532
4.4
2023-08-01 CVE-2023-31426 Information Exposure Through Log Files vulnerability in Broadcom Fabric Operating System
The Brocade Fabric OS Commands “configupload” and “configdownload” before Brocade Fabric OS v9.1.1c, v8.2.3d, v9.2.0 print scp, sftp, ftp servers passwords in supportsave.
network
low complexity
broadcom CWE-532
6.5
2023-07-26 CVE-2023-20891 Information Exposure Through Log Files vulnerability in VMWare products
The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials in hex encoding in platform system audit logs. A malicious non-admin user who has access to the platform system audit logs can access hex encoded CF API admin credentials and can push new malicious versions of an application.
network
low complexity
vmware CWE-532
6.5
2023-07-20 CVE-2023-32446 Information Exposure Through Log Files vulnerability in Dell Wyse Thinos 9.4.1141
Dell Wyse ThinOS versions prior to 2303 (9.4.1141) contain a sensitive information disclosure vulnerability.
local
low complexity
dell CWE-532
5.5
2023-07-20 CVE-2023-32447 Information Exposure Through Log Files vulnerability in Dell Wyse Thinos
Dell Wyse ThinOS versions prior to 2306 (9.4.2103) contain a sensitive information disclosure vulnerability.
local
low complexity
dell CWE-532
5.5
2023-07-20 CVE-2023-32455 Information Exposure Through Log Files vulnerability in Dell Wyse Thinos
Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulnerability.
local
low complexity
dell CWE-532
5.5
2023-07-19 CVE-2023-26023 Information Exposure Through Log Files vulnerability in IBM Cloud PAK for Data 4.0
Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerability to conduct further attacks.
network
low complexity
ibm CWE-532
7.5
2023-07-19 CVE-2023-26026 Information Exposure Through Log Files vulnerability in IBM Cloud PAK for Data 4.0
Planning Analytics Cartridge for Cloud Pak for Data 4.0 exposes sensitive information in logs which could lead an attacker to exploit this vulnerability to conduct further attacks.
network
low complexity
ibm CWE-532
7.5
2023-07-14 CVE-2023-37224 Information Exposure Through Log Files vulnerability in Archerirm Archer
An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain sensitive information via the log files.
local
low complexity
archerirm CWE-532
5.5