Vulnerabilities > Information Exposure Through Log Files

DATE CVE VULNERABILITY TITLE RISK
2022-08-31 CVE-2022-39046 Information Exposure Through Log Files vulnerability in multiple products
An issue was discovered in the GNU C Library (glibc) 2.36.
network
low complexity
gnu netapp CWE-532
5.3
2022-08-29 CVE-2022-0718 Information Exposure Through Log Files vulnerability in multiple products
A flaw was found in python-oslo-utils.
network
low complexity
openstack redhat debian CWE-532
4.9
2022-08-26 CVE-2021-32570 Information Exposure Through Log Files vulnerability in Ericsson Network Manager
In Ericsson Network Manager (ENM) releases before 21.2, users belonging to the same AMOS authorization group can retrieve the data from certain log files.
network
low complexity
ericsson CWE-532
4.9
2022-08-25 CVE-2022-23715 Information Exposure Through Log Files vulnerability in Elastic Cloud Enterprise
A flaw was discovered in ECE before 3.4.0 that might lead to the disclosure of sensitive information such as user passwords and Elasticsearch keystore settings values in logs such as the audit log or deployment logs in the Logging and Monitoring cluster.
network
low complexity
elastic CWE-532
6.5
2022-08-18 CVE-2022-29550 Information Exposure Through Log Files vulnerability in Qualys Cloud Agent 4.8.049
An issue was discovered in Qualys Cloud Agent 4.8.0-49.
local
low complexity
qualys CWE-532
5.5
2022-08-17 CVE-2022-38149 Information Exposure Through Log Files vulnerability in Hashicorp Consul Template
HashiCorp Consul Template up to 0.27.2, 0.28.2, and 0.29.1 may expose the contents of Vault secrets in the error returned by the *template.Template.Execute method, when given a template using Vault secret contents incorrectly.
network
low complexity
hashicorp CWE-532
7.5
2022-08-12 CVE-2022-20278 Information Exposure Through Log Files vulnerability in Google Android 13.0
In Accounts, there is a possible way to write sensitive information to the system log due to insufficient log filtering.
local
low complexity
google CWE-532
5.5
2022-08-10 CVE-2022-31674 Information Exposure Through Log Files vulnerability in VMWare Vrealize Operations
VMware vRealize Operations contains an information disclosure vulnerability.
network
low complexity
vmware CWE-532
4.3
2022-08-10 CVE-2022-38133 Information Exposure Through Log Files vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2022.04.3 the private SSH key could be written to the server log in some cases
network
low complexity
jetbrains CWE-532
5.3
2022-08-05 CVE-2022-29071 Information Exposure Through Log Files vulnerability in Arista Cloudvision Portal
This advisory documents an internally found vulnerability in the on premises deployment model of Arista CloudVision Portal (CVP) where under a certain set of conditions, user passwords can be leaked in the Audit and System logs.
local
low complexity
arista CWE-532
5.5