Vulnerabilities > Information Exposure Through Log Files

DATE CVE VULNERABILITY TITLE RISK
2023-04-19 CVE-2022-2084 Information Exposure Through Log Files vulnerability in Canonical Cloud-Init and Ubuntu Linux
Sensitive data could be exposed in world readable logs of cloud-init before version 22.3 when schema failures are reported.
local
low complexity
canonical CWE-532
5.5
2023-04-19 CVE-2023-30610 Information Exposure Through Log Files vulnerability in Amazon Aws-Sigv4
aws-sigv4 is a rust library for low level request signing in the aws cloud platform.
local
low complexity
amazon CWE-532
5.5
2023-04-04 CVE-2022-48228 Information Exposure Through Log Files vulnerability in Gbgplc Acuant Asureid Sentinel
An issue was discovered in Acuant AsureID Sentinel before 5.2.149.
local
low complexity
gbgplc CWE-532
5.5
2023-04-03 CVE-2022-43772 Information Exposure Through Log Files vulnerability in Hitachi Vantara Pentaho Business Analytics Server
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.0 and 9.3.0.1, including 8.3.x with the Big Data Plugin expose the username and password of clusters in clear text into system logs. 
network
low complexity
hitachi CWE-532
6.5
2023-03-24 CVE-2021-3684 Information Exposure Through Log Files vulnerability in Redhat Openshift Assisted Installer
A vulnerability was found in OpenShift Assisted Installer.
local
low complexity
redhat CWE-532
5.5
2023-03-23 CVE-2023-20859 Information Exposure Through Log Files vulnerability in VMWare products
In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attempts to revoke a Vault batch token.
local
low complexity
vmware CWE-532
5.5
2023-03-21 CVE-2023-25687 Information Exposure Through Log Files vulnerability in IBM Security KEY Lifecycle Manager
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an authenticated user to obtain sensitive information from log files.
network
low complexity
ibm CWE-532
4.3
2023-02-27 CVE-2023-23505 Information Exposure Through Log Files vulnerability in Apple products
A privacy issue was addressed with improved private data redaction for log entries.
local
low complexity
apple CWE-532
3.3
2023-02-23 CVE-2023-0815 Information Exposure Through Log Files vulnerability in Opennms Horizon
Potential Insertion of Sensitive Information into Jetty Log Files in multiple versions of OpenNMS Meridian and Horizon could allow disclosure of usernames and passwords if the logging level is set to debug. Users should upgrade to Meridian 2023.1.0 or newer, or Horizon 31.0.4.
network
low complexity
opennms CWE-532
6.5
2023-02-20 CVE-2022-48319 Information Exposure Through Log Files vulnerability in Checkmk 2.0.0/2.1.0
Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to gain access to the host secret through the unprotected agent updater log file.
local
low complexity
checkmk CWE-532
5.5