Vulnerabilities > Information Exposure Through Log Files

DATE CVE VULNERABILITY TITLE RISK
2021-04-12 CVE-2021-24024 Information Exposure Through Log Files vulnerability in Fortinet Fortiadc
A clear text storage of sensitive information into log file vulnerability in FortiADCManager 5.3.0 and below, 5.2.1 and below and FortiADC 5.3.7 and below may allow a remote authenticated attacker to read other local users' password in log files.
network
low complexity
fortinet CWE-532
6.5
2021-04-01 CVE-2021-23924 Information Exposure Through Log Files vulnerability in Devolutions Server
An issue was discovered in Devolutions Server before 2020.3.
network
low complexity
devolutions CWE-532
7.5
2021-03-26 CVE-2021-22184 Information Exposure Through Log Files vulnerability in Gitlab
An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that wasn't properly redacted.
local
low complexity
gitlab CWE-532
5.5
2021-03-25 CVE-2021-25350 Information Exposure Through Log Files vulnerability in Samsung Account 10.7.07/10.8.0.4
Information Exposure vulnerability in Samsung Account prior to version 12.1.1.3 allows physically proximate attackers to access user information via log.
low complexity
samsung CWE-532
3.9
2021-03-22 CVE-2021-22310 Information Exposure Through Log Files vulnerability in Huawei products
There is an information leakage vulnerability in some huawei products.
local
low complexity
huawei CWE-532
4.4
2021-03-15 CVE-2021-3167 Information Exposure Through Log Files vulnerability in Cloudera Data Engineering 1.3.0
In Cloudera Data Engineering (CDE) 1.3.0, JWT authentication tokens are exposed to administrators in virtual cluster server logs.
network
low complexity
cloudera CWE-532
6.5
2021-02-11 CVE-2021-25688 Information Exposure Through Log Files vulnerability in Teradici Pcoip Graphics Agent and Pcoip Standard Agent
Under certain conditions, Teradici PCoIP Agents for Windows prior to version 20.10.0 and Teradici PCoIP Agents for Linux prior to version 21.01.0 may log parts of a user's password in the application logs.
local
low complexity
teradici CWE-532
5.5
2021-02-10 CVE-2021-22133 Information Exposure Through Log Files vulnerability in Elastic APM Agent
The Elastic APM agent for Go versions before 1.11.0 can leak sensitive HTTP header information when logging the details during an application panic.
low complexity
elastic CWE-532
2.4
2021-02-10 CVE-2020-7021 Information Exposure Through Log Files vulnerability in Elastic Elasticsearch
Elasticsearch versions before 7.10.0 and 6.8.14 have an information disclosure issue when audit logging and the emit_request_body option is enabled.
network
low complexity
elastic CWE-532
4.9
2021-02-08 CVE-2021-20359 Information Exposure Through Log Files vulnerability in IBM Cloud PAK for Automation 20.0.2/20.0.3
IBM Cloud Pak for Automation 20.0.3, 20.0.2-IF002 - Business Automation Application Designer Component stores potentially sensitive information in log files that could be obtained by an unauthorized user.
network
low complexity
ibm CWE-532
6.5