Vulnerabilities > Information Exposure Through Log Files

DATE CVE VULNERABILITY TITLE RISK
2020-06-10 CVE-2020-13223 Information Exposure Through Log Files vulnerability in Hashicorp Vault
HashiCorp Vault and Vault Enterprise logged proxy environment variables that potentially included sensitive credentials.
network
low complexity
hashicorp CWE-532
5.0
2020-06-06 CVE-2020-13881 Information Exposure Through Log Files vulnerability in multiple products
In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used.
4.3
2020-06-04 CVE-2020-11094 Information Exposure Through Log Files vulnerability in Octobercms Debugbar
The October CMS debugbar plugin before version 3.1.0 contains a feature where it will log all requests (and all information pertaining to each request including session data) whenever it is enabled.
6.8
2020-06-03 CVE-2020-3281 Information Exposure Through Log Files vulnerability in Cisco Digital Network Architecture Center
A vulnerability in the audit logging component of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to view sensitive information in clear text.
network
low complexity
cisco CWE-532
4.0
2020-05-13 CVE-2020-2004 Information Exposure Through Log Files vulnerability in Paloaltonetworks Globalprotect
Under certain circumstances a user's password may be logged in cleartext in the PanGPS.log diagnostic file when logs are collected for troubleshooting on GlobalProtect app (also known as GlobalProtect Agent) for MacOS and Windows.
local
low complexity
paloaltonetworks CWE-532
1.7
2020-05-13 CVE-2020-11932 Information Exposure Through Log Files vulnerability in Canonical Subiquity
It was discovered that the Subiquity installer for Ubuntu Server logged the LUKS full disk encryption password if one was entered.
local
low complexity
canonical CWE-532
2.1
2020-05-11 CVE-2020-1698 Information Exposure Through Log Files vulnerability in Redhat Keycloak
A flaw was found in keycloak in versions before 9.0.0.
local
low complexity
redhat CWE-532
5.5
2020-04-22 CVE-2020-10712 Information Exposure Through Log Files vulnerability in Redhat Openshift Container Platform
A flaw was found in OpenShift Container Platform version 4.1 and later.
network
low complexity
redhat CWE-532
8.2
2020-04-21 CVE-2020-11968 Information Exposure Through Log Files vulnerability in Evenroute Iqrouter Firmware 3.3.1
In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control.
network
low complexity
evenroute CWE-532
7.5
2020-04-08 CVE-2020-1624 Information Exposure Through Log Files vulnerability in Juniper Junos OS Evolved 18.3/19.1
A local, authenticated user with shell can obtain the hashed values of login passwords and shared secrets via raw objmon configuration files.
local
low complexity
juniper CWE-532
2.1