Vulnerabilities > Information Exposure Through Log Files

DATE CVE VULNERABILITY TITLE RISK
2020-10-15 CVE-2020-11643 Information Exposure Through Log Files vulnerability in Br-Automation products
An information disclosure vulnerability in B&R GateManager 4260 and 9250 versions <9.0.20262 and GateManager 8250 versions <9.2.620236042 allows authenticated users to view information of devices belonging to foreign domains.
network
low complexity
br-automation CWE-532
6.5
2020-10-08 CVE-2020-5389 Information Exposure Through Log Files vulnerability in Dell EMC Openmanage Integration for Microsoft System Center
Dell EMC OpenManage Integration for Microsoft System Center (OMIMSSC) for SCCM and SCVMM versions prior to 7.2.1 contain an information disclosure vulnerability.
network
low complexity
dell CWE-532
6.5
2020-10-06 CVE-2020-26605 Information Exposure Through Log Files vulnerability in Google Android 10.0/11.0
An issue was discovered on Samsung mobile devices with Q(10.0) and R(11.0) (Exynos chipsets) software.
network
low complexity
google CWE-532
7.5
2020-10-06 CVE-2020-25987 Information Exposure Through Log Files vulnerability in Monocms 1.0
MonoCMS Blog 1.0 stores hard-coded admin hashes in the log.xml file in the source files for MonoCMS Blog.
network
low complexity
monocms CWE-532
7.5
2020-10-01 CVE-2020-9486 Information Exposure Through Log Files vulnerability in Apache Nifi
In Apache NiFi 1.10.0 to 1.11.4, the NiFi stateless execution engine produced log output which included sensitive property values.
network
low complexity
apache CWE-532
7.5
2020-09-25 CVE-2020-15370 Information Exposure Through Log Files vulnerability in Broadcom Fabric Operating System
Brocade Fabric OS versions before Brocade Fabric OS v7.4.2g could allow an authenticated, remote attacker to view a user password in cleartext.
network
low complexity
broadcom CWE-532
6.5
2020-09-11 CVE-2020-14330 Information Exposure Through Log Files vulnerability in multiple products
An Improper Output Neutralization for Logs flaw was found in Ansible when using the uri module, where sensitive data is exposed to content and json output.
local
low complexity
redhat debian CWE-532
5.5
2020-09-09 CVE-2020-2044 Information Exposure Through Log Files vulnerability in Paloaltonetworks Pan-Os
An information exposure through log file vulnerability where an administrator's password or other sensitive information may be logged in cleartext while using the CLI in Palo Alto Networks PAN-OS software.
local
low complexity
paloaltonetworks CWE-532
3.3
2020-09-09 CVE-2020-2043 Information Exposure Through Log Files vulnerability in Paloaltonetworks Pan-Os
An information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Palo Alto Networks PAN-OS software when the after-change-detail custom syslog field is enabled for configuration logs and the sensitive field appears multiple times in one log entry.
local
low complexity
paloaltonetworks CWE-532
3.3
2020-09-09 CVE-2020-24566 Information Exposure Through Log Files vulnerability in Octopus Deploy
In Octopus Deploy 2020.3.x before 2020.3.4 and 2020.4.x before 2020.4.1, if an authenticated user creates a deployment or runbook process using Azure steps and sets the step's execution location to run on the server/worker, then (under certain circumstances) the account password is exposed in cleartext in the verbose task logs output.
network
low complexity
octopus CWE-532
7.5