Vulnerabilities > Information Exposure Through Log Files

DATE CVE VULNERABILITY TITLE RISK
2021-10-04 CVE-2021-39900 Information Exposure Through Log Files vulnerability in Gitlab
Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs.
network
low complexity
gitlab CWE-532
2.7
2021-09-24 CVE-2021-39246 Information Exposure Through Log Files vulnerability in Torproject TOR Browser
Tor Browser through 10.5.6 and 11.x through 11.0a4 allows a correlation attack that can compromise the privacy of visits to v2 onion addresses.
low complexity
torproject CWE-532
6.1
2021-09-14 CVE-2021-23046 Information Exposure Through Log Files vulnerability in F5 Big-Ip Access Policy Manager
On all versions of Guided Configuration before 8.0.0, when a configuration that contains secure properties is created and deployed from Access Guided Configuration (AGC), secure properties are logged in restnoded logs.
network
low complexity
f5 CWE-532
4.9
2021-09-07 CVE-2021-27022 Information Exposure Through Log Files vulnerability in Puppet and Puppet Enterprise
A flaw was discovered in bolt-server and ace where running a task with sensitive parameters results in those sensitive parameters being logged when they should not be.
network
low complexity
puppet CWE-532
4.9
2021-08-31 CVE-2021-22929 Information Exposure Through Log Files vulnerability in Brave
An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps of connections to V2 onion domains in tor.log.
local
low complexity
brave CWE-532
6.1
2021-08-30 CVE-2021-22024 Information Exposure Through Log Files vulnerability in VMWare products
The vRealize Operations Manager API (8.x prior to 8.5) contains an arbitrary log-file read vulnerability.
network
low complexity
vmware CWE-532
7.5
2021-08-30 CVE-2021-27019 Information Exposure Through Log Files vulnerability in Puppet Enterprise and Puppetdb
PuppetDB logging included potentially sensitive system information.
network
low complexity
puppet CWE-532
4.3
2021-08-23 CVE-2021-39291 Information Exposure Through Log Files vulnerability in Netmodule Router Software 4.3.0.0/4.4.0.0
Certain NetModule devices allow credentials via GET parameters to CLI-PHP.
network
low complexity
netmodule CWE-532
8.8
2021-08-16 CVE-2021-36278 Information Exposure Through Log Files vulnerability in Dell EMC Powerscale Onefs
Dell EMC PowerScale OneFS versions 8.2.x, 9.1.0.x, and 9.1.1.1 contain a sensitive information exposure vulnerability in log files.
local
low complexity
dell CWE-532
5.5
2021-08-06 CVE-2021-26998 Information Exposure Through Log Files vulnerability in Netapp Cloud Manager
NetApp Cloud Manager versions prior to 3.9.9 log sensitive information that is available only to authenticated users.
network
low complexity
netapp CWE-532
4.3