← Back
CWE-200

10,496 CVEs • Abstraction: Class • Likelihood of Exploit: High

Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

JSON object

Loading...

CVEs (10,496)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Parceljs
1Parcel
Nov 21, 2024
Sep 21, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in HMRServer.js in Parcel parcel-bundler. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSocket server, which is used for HMR (Hot Module Repl...Show more
An issue was discovered in HMRServer.js in Parcel parcel-bundler. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSocket server, which is used for HMR (Hot Module Replacement). Anyone can receive the HMR message sent by the WebSocket server via a ws://127.0.0.1 connection (with a random TCP port number) from any origin. The random port number can be found by connecting to http://127.0.0.1 and reading the "new WebSocket" line in the source code.Show less
1Browserify Hot Module Replacement Project
1Browserify Hot Module Replacement
Nov 21, 2024
Sep 21, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Browserify-HMR. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSocket server, which is used for HMR (Hot Module Replacement). Anyone can re...Show more
An issue was discovered in Browserify-HMR. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSocket server, which is used for HMR (Hot Module Replacement). Anyone can receive the HMR message sent by the WebSocket server via a ws://127.0.0.1:3123/ connection from any origin.Show less
1Gitolite
1Gitolite
Nov 21, 2024
Sep 21, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
gitolite before commit fa06a34 might allow local users to read arbitrary files in repositories via vectors related to the user umask when running gitolite setup.
1Apache
1Mesos
Jun 17, 2026
Sep 21, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos versions pre-1.4.2, 1.5.0, 1.5.1, 1.6.0 the comparison of the generated HMAC value agains...Show more
Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos versions pre-1.4.2, 1.5.0, 1.5.1, 1.6.0 the comparison of the generated HMAC value against the provided signature in the JWT implementation used is vulnerable to a timing attack because instead of a constant-time string comparison routine a standard `==` operator has been used. A malicious actor can therefore abuse the timing difference of when the JWT validation function returns to reveal the correct HMAC value.Show less
1Ibm
1Db2
Nov 21, 2024
Sep 21, 2018
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability in db2cacpy that could allow a local user to read any file on the system. IBM X-Force ID: 145502.
1Ibm
1Sterling B2b Integrator
Nov 21, 2024
Sep 20, 2018
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
IBM Sterling B2B Integrator Standard Edition 5.2.6.0 and 6.2.6.1 could allow a local user to obtain highly sensitive information during a short time period when installation is occurring. IBM X-Force ID: 149607.
1Elastic
1Elasticsearch
Nov 21, 2024
Sep 19, 2018
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API. The Elasticsearch _cluster/settings API, when queried, could leak sen...Show more
Elasticsearch Alerting and Monitoring in versions before 6.4.1 or 5.6.12 have an information disclosure issue when secrets are configured via the API. The Elasticsearch _cluster/settings API, when queried, could leak sensitive configuration information such as passwords, tokens, or usernames. This could allow an authenticated Elasticsearch user to improperly view these details.Show less
1Elastic
1Elasticsearch
Nov 21, 2024
Sep 19, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are set using the _snapshot API they can be exposed as plain text by users...Show more
In Elasticsearch versions 6.0.0-beta1 to 6.2.4 a disclosure flaw was found in the _snapshot API. When the access_key and security_key parameters are set using the _snapshot API they can be exposed as plain text by users able to query the _snapshot API.Show less
1Circontrol
1Circarlife Scada
Nov 21, 2024
Sep 18, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is system software information disclosure due to lack of authentication for /html/device-id.
1Google
1Android
Nov 21, 2024
Sep 18, 2018
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, when flashing image using FastbootLib if size is not divisible by block size, information leak occurs.
1Redhat
2Jboss Enterprise Application Platform
Undertow
Nov 21, 2024
Sep 18, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBu...Show more
An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain data from previous requests.Show less
1Oracle
1Webcenter Interaction
Nov 21, 2024
Sep 18, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The portal component is delivered with an insecure default User Profile community configuration that allows anonymous users to retrieve the account n...Show more
An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The portal component is delivered with an insecure default User Profile community configuration that allows anonymous users to retrieve the account names of all portal users via /portal/server.pt/user/user/ requests. When WCI is synchronised with Active Directory (AD), this vulnerability can expose the account names of all AD users. NOTE: this CVE is assigned by MITRE and isn't validated by Oracle because Oracle WebCenter Interaction Portal is out of support.Show less
1Insteon
1Hub 2245 222 Firmware
Nov 21, 2024
Sep 17, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An exploitable information leak vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implementation incorrectly checks the number of GET parameters supplied, leading to an arbitrarily contro...Show more
An exploitable information leak vulnerability exists in Insteon Hub running firmware version 1012. The HTTP server implementation incorrectly checks the number of GET parameters supplied, leading to an arbitrarily controlled information leak on the whole device memory. An attacker can send an authenticated HTTP request to trigger this vulnerability.Show less
1I4a
1Donlinkage
Nov 21, 2024
Sep 16, 2018
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
An issue was discovered in DonLinkage 6.6.8. It allows remote attackers to obtain potentially sensitive information via a direct request for files/temporary.txt.
1Lg
1Supersign Cms
Nov 21, 2024
Sep 14, 2018
N/A· v4
8.6 HIGH· v3
7.8 HIGH· v2
LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.
1Torproject
1Tor Browser
Nov 21, 2024
Sep 14, 2018
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Tor Browser on Windows before 8.0 allows remote attackers to bypass the intended anonymity feature and discover a client IP address, a different vulnerability than CVE-2017-16541. User interaction is required to trigger...Show more
Tor Browser on Windows before 8.0 allows remote attackers to bypass the intended anonymity feature and discover a client IP address, a different vulnerability than CVE-2017-16541. User interaction is required to trigger this vulnerability.Show less
1Ibm
1Maximo Asset Management
Nov 21, 2024
Sep 13, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
IBM Maximo Asset Management 7.6 through 7.6.3 could allow an unauthenticated attacker to obtain sensitive information from error messages. IBM X-Force ID: 145967.
1F5
1Big Ip Access Policy Manager
Nov 21, 2024
Sep 13, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in BIG-IP APM portal access 11.5.1-11.5.7, 11.6.0-11.6.3, and 12.1.0-12.1.3 discloses the BIG-IP software version in rewritten pages.
1Microsoft
3Chakracore
EdgeInternet Explorer
Jun 17, 2026
Sep 13, 2018
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft browsers, aka "Scripting Engine Information Disclosure Vulnerability." This affects ChakraC...Show more
An information disclosure vulnerability exists when the scripting engine does not properly handle objects in memory in Microsoft browsers, aka "Scripting Engine Information Disclosure Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge.Show less
1Microsoft
7Windows 10
Windows 7Windows 8.1+4 more
Jun 17, 2026
Sep 13, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Wind...Show more
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka "Windows Kernel Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8336, CVE-2018-8419, CVE-2018-8442, CVE-2018-8443, CVE-2018-8445.Show less