Vulnerabilities > Information Exposure Through Log Files

DATE CVE VULNERABILITY TITLE RISK
2019-12-15 CVE-2014-3536 Information Exposure Through Log Files vulnerability in Redhat Cloudforms Management Engine 5.0
CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration
local
low complexity
redhat CWE-532
5.5
2019-12-12 CVE-2019-10695 Information Exposure Through Log Files vulnerability in Puppet Continuous Delivery
When using the cd4pe::root_configuration task to configure a Continuous Delivery for PE installation, the root user’s username and password were exposed in the job’s Job Details pane in the PE console.
network
low complexity
puppet CWE-532
6.5
2019-12-06 CVE-2019-11293 Information Exposure Through Log Files vulnerability in Cloudfoundry Cf-Deployment
Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter.
network
low complexity
cloudfoundry CWE-532
6.5
2019-11-27 CVE-2019-10195 Information Exposure Through Log Files vulnerability in multiple products
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations.
network
low complexity
freeipa fedoraproject CWE-532
6.5
2019-11-26 CVE-2019-11290 Information Exposure Through Log Files vulnerability in Cloudfoundry Cf-Deployment
Cloud Foundry UAA Release, versions prior to v74.8.0, logs all query parameters to tomcat’s access file.
network
low complexity
cloudfoundry CWE-532
7.5
2019-11-21 CVE-2019-19039 Information Exposure Through Log Files vulnerability in multiple products
__btrfs_free_extent in fs/btrfs/extent-tree.c in the Linux kernel through 5.3.12 calls btrfs_print_leaf in a certain ENOENT case, which allows local users to obtain potentially sensitive information about register values via the dmesg program.
local
low complexity
linux debian canonical CWE-532
5.5
2019-11-15 CVE-2019-6662 Information Exposure Through Log Files vulnerability in F5 products
On BIG-IP 13.1.0-13.1.1.4, sensitive information is logged into the local log files and/or remote logging targets when restjavad processes an invalid request.
network
low complexity
f5 CWE-532
6.5
2019-11-14 CVE-2012-1156 Information Exposure Through Log Files vulnerability in multiple products
Moodle before 2.2.2 has users' private files included in course backups
network
low complexity
moodle fedoraproject redhat CWE-532
7.5
2019-11-13 CVE-2019-3649 Information Exposure Through Log Files vulnerability in Mcafee Advanced Threat Defense
Information Disclosure vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows remote authenticated attackers to gain access to hashed credentials via carefully constructed POST request extracting incorrectly recorded data from log files.
network
low complexity
mcafee CWE-532
6.5
2019-11-07 CVE-2013-1771 Information Exposure Through Log Files vulnerability in Monkey-Project Monkey
The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo.
network
low complexity
monkey-project CWE-532
7.5