Vulnerabilities > Information Exposure Through Log Files

DATE CVE VULNERABILITY TITLE RISK
2023-10-26 CVE-2023-31422 Information Exposure Through Log Files vulnerability in Elastic Kibana 8.10.0
An issue was discovered by Elastic whereby sensitive information is recorded in Kibana logs in the event of an error.
network
low complexity
elastic CWE-532
7.5
2023-10-26 CVE-2023-46667 Information Exposure Through Log Files vulnerability in Elastic Fleet Server 8.10.0/8.10.2
An issue was discovered in Fleet Server >= v8.10.0 and < v8.10.3 where Agent enrolment tokens are being inserted into the Fleet Server’s log file in plain text.
network
low complexity
elastic CWE-532
8.1
2023-10-26 CVE-2023-46668 Information Exposure Through Log Files vulnerability in Elastic Endpoint 7.9.0/8.10.3
If Elastic Endpoint (v7.9.0 - v8.10.3) is configured to use a non-default option in which the logging level is explicitly set to debug, and when Elastic Agent is simultaneously configured to collect and send those logs to Elasticsearch, then Elastic Agent API keys can be viewed in Elasticsearch in plaintext.
network
low complexity
elastic CWE-532
critical
9.1
2023-10-25 CVE-2023-40405 Information Exposure Through Log Files vulnerability in Apple Macos 14.0
A privacy issue was addressed with improved private data redaction for log entries.
local
low complexity
apple CWE-532
3.3
2023-10-25 CVE-2023-40425 Information Exposure Through Log Files vulnerability in Apple Macos
A privacy issue was addressed with improved private data redaction for log entries.
local
low complexity
apple CWE-532
4.4
2023-10-25 CVE-2023-41254 Information Exposure Through Log Files vulnerability in Apple products
A privacy issue was addressed with improved private data redaction for log entries.
local
low complexity
apple CWE-532
5.5
2023-10-25 CVE-2023-42857 Information Exposure Through Log Files vulnerability in Apple Ipados and Macos
A privacy issue was addressed with improved private data redaction for log entries.
local
low complexity
apple CWE-532
3.3
2023-10-20 CVE-2023-44483 Information Exposure Through Log Files vulnerability in Apache Santuario XML Security for Java
All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to an issue where a private key may be disclosed in log files when generating an XML Signature and logging with debug level is enabled. Users are recommended to upgrade to version 2.2.6, 2.3.4, or 3.0.3, which fixes this issue.
network
low complexity
apache CWE-532
6.5
2023-10-19 CVE-2023-45809 Information Exposure Through Log Files vulnerability in Torchbox Wagtail
Wagtail is an open source content management system built on Django.
network
low complexity
torchbox CWE-532
2.7
2023-10-19 CVE-2023-45825 Information Exposure Through Log Files vulnerability in YDB Ydb-Go-Sdk
ydb-go-sdk is a pure Go native and database/sql driver for the YDB platform.
local
low complexity
ydb CWE-532
5.5