← Back
CWE-200

10,479 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,479)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Freeipa
2Fedora
Freeipa
Jun 17, 2026
Nov 27, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user...Show more
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way that FreeIPA's batch processing API logged operations. This included passing user passwords in clear text on FreeIPA masters. Batch processing of commands with passwords as arguments or options is not performed by default in FreeIPA but is possible by third-party components. An attacker having access to system logs on FreeIPA masters could use this flaw to produce log file content with passwords exposed.Show less
2Debian
Lilo Project
2Debian Linux
Lilo
Nov 21, 2024
Nov 26, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
lilo-uuid-diskid causes lilo.conf to be world-readable in lilo 23.1.
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraSquid+1 more
Jun 17, 2026
Nov 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte v...Show more
An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits within heap memory allocation. This information reduces ASLR protections and may aid attackers isolating memory areas to target for remote code execution attacks.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Nov 26, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition 11.3 through 12.3 when a sub group epic is added to a public group. It has Incorrect Access Control.
1Gitlab
1Gitlab
Jun 17, 2026
Nov 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition 8.15 through 12.4 in the Comments Search feature provided by the Elasticsearch integration. It has Incorrect Access Control.
1Cloudera
1Cdh
Nov 21, 2024
Nov 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Cloudera CDH before 5.9 has Potentially Sensitive Information in Diagnostic Support Bundles.
1Cloudera
1Cloudera Manager
Nov 21, 2024
Nov 26, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is Sensitive Information in Cloudera Manager before 5.4.6 Diagnostic Support Bundles.
1Openstack
1Nova
Nov 21, 2024
Nov 26, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC2_SECRET_KEY (equivalent to a password). Exposing the EC2_ACCESS_KEY via http or tools that allow ma...Show more
OpenStack Nova before 2012.1 allows someone with access to an EC2_ACCESS_KEY (equivalent to a username) to obtain the EC2_SECRET_KEY (equivalent to a password). Exposing the EC2_ACCESS_KEY via http or tools that allow man-in-the-middle over https could allow an attacker to easily obtain the EC2_SECRET_KEY. An attacker could also presumably brute force values for EC2_ACCESS_KEY.Show less
1Fedoraproject
1389 Directory Server
Jun 17, 2026
Nov 25, 2019
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker...Show more
A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.Show less
1Redhat
1Ansible
Jun 17, 2026
Nov 25, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are not set properly. service_account_contents() which is common...Show more
A flaw was found in ansible 2.8.0 before 2.8.4. Fields managing sensitive data should be set as such by no_log feature. Some of these fields in GCP modules are not set properly. service_account_contents() which is common class for all gcp modules is not setting no_log to True. Any sensitive data managed by that function would be leak as an output when running ansible playbooks.Show less
1Google
1Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
7.4 HIGH· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in Blink in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
4Debian
FedoraprojectLibuser Project+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Jan 23, 2026
Nov 25, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
libuser has information disclosure when moving user's home directory
2Fedoraproject
Gnome
2Fedora
Gnome System Log
Nov 21, 2024
Nov 25, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
gnome-system-log polkit policy allows arbitrary files on the system to be read
1Hp
1Thinpro Linux
Jun 17, 2026
Nov 22, 2019
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
If a local user has been configured and logged in, an unauthenticated attacker with physical access may be able to extract sensitive information onto a local drive.
1Boldgrid
1W3 Total Cache
Nov 21, 2024
Nov 22, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
W3 Total Cache before 0.9.2.5 exposes sensitive cached database information which allows remote attackers to download this information via their hash keys.
1Boldgrid
1W3 Total Cache
Nov 21, 2024
Nov 22, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
W3 Total Cache before 0.9.2.5 generates hash keys insecurely which allows remote attackers to predict the values of the hashes.
1Boldgrid
1W3 Total Cache
Nov 21, 2024
Nov 22, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
W3 Total Cache before 0.9.2.5 allows remote attackers to retrieve password hash information due to insecure storage of database cache files.
1Loftek
1Nexus 543 Firmware
Nov 21, 2024
Nov 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Loftek Nexus 543 IP Camera allows remote attackers to obtain (1) IP addresses via a request to get_realip.cgi or (2) firmware versions (ui and system), timestamp, serial number, p2p port number, and wifi status via a...Show more
The Loftek Nexus 543 IP Camera allows remote attackers to obtain (1) IP addresses via a request to get_realip.cgi or (2) firmware versions (ui and system), timestamp, serial number, p2p port number, and wifi status via a request to get_status.cgi.Show less
1Schneider Electric
10140 Cpu6x Firmware
140 Noc 77101 Firmware140 Noc 78x00 Firmware+7 more
Jun 17, 2026
Nov 20, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security...Show more
A CWE-200: Information Exposure vulnerability exists in Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions), which could cause the disclosure of FTP hardcoded credentials when using the Web server of the controller on an unsecure network.Show less
3Canonical
DebianPostgresql
3Debian Linux
PostgresqlUbuntu Linux
Nov 21, 2024
Nov 20, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for a...Show more
contrib/pgcrypto in PostgreSQL before 9.0.20, 9.1.x before 9.1.16, 9.2.x before 9.2.11, 9.3.x before 9.3.7, and 9.4.x before 9.4.2 uses different error responses when an incorrect key is used, which makes it easier for attackers to obtain the key via a brute force attack.Show less