CWE-200
10,521 CVEs • Abstraction: Class • Likelihood of Exploit: High
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVEs (10,521)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Node Opencv Project 1Node Opencv Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 node-opencv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
opencv.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Openssl.js Project 1Openssl.js Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 openssl.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Node Openssl Project 1Node Openssl Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 node-openssl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Node Opensl Project 1Node Opensl Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 node-opensl was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
babelcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
1Mssql Node Project 1Mssql Node Nov 21, 2024 Jun 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 mssql-node was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
gruntcli was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
nodemssql was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
mssql.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. |
An issue was discovered in OTRS 6.0.x before 6.0.7. An attacker who is logged into OTRS as a customer can use the ticket overview screen to disclose internal article information of their customer tickets. |
1Ibm 3Security Access Manager Security Access Manager For MobileSecurity Access Manager For WebNov 21, 2024 Jun 6, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport...Show more |
1Ibm 3Security Access Manager Security Access Manager For MobileSecurity Access Manager For WebNov 21, 2024 Jun 6, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Security Access Manager Appliance 7.0.0, 8.0.0 through 8.0.1.6, and 9.0.0 through 9.0.3.1 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. IBM...Show more |
A exposure of sensitive information vulnerability exists in Jenkins Gitlab Hook Plugin 1.4.2 and older in gitlab_notifier.rb, views/gitlab_notifier/global.erb that allows attackers with local Jenkins master file system a...Show more |
1Philips 18Avalon Fetal/maternal Monitors Fm20 Firmware Avalon Fetal/maternal Monitors Fm30 FirmwareAvalon Fetal/maternal Monitors Fm40 Firmware+15 moreNov 21, 2024 Jun 5, 2018 N/A· v4 5.3 MEDIUM· v3 2.9 LOW· v2 IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM...Show more |
A exposure of sensitive information vulnerability exists in Jenkins Black Duck Detect Plugin 1.4.0 and older in DetectPostBuildStepDescriptor.java that allows attackers with Overall/Read access to connect to an attacker-...Show more |
A exposure of sensitive information vulnerability exists in Jenkins Black Duck Hub Plugin 4.0.0 and older in PostBuildScanDescriptor.java that allows attackers with Overall/Read access to connect to an attacker-specified...Show more |
A exposure of sensitive information vulnerability exists in Jenkins Kubernetes Plugin 1.7.0 and older in ContainerExecDecorator.java that results in sensitive variables such as passwords being written to logs. |
1Jenkins 1Github Pull Request Builder Nov 21, 2024 Jun 5, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin 1.41.0 and older in GhprbGitHubAuth.java that allows attackers with Overall/Read access to connect to an attacker-spe...Show more |
A exposure of sensitive information vulnerability exists in Jenkins GitHub Plugin 1.29.0 and older in GitHubServerConfig.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using a...Show more |