CWE-209
607 CVEs • Abstraction: Base • Likelihood of Exploit: High
Generation of Error Message Containing Sensitive Information
The product generates an error message that includes sensitive information about its environment, users, or associated data.
CVEs (607)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Exposure of System Data to an Unauthorized Control Sphere vulnerability in web UI of Argo CD allows attacker to cause leaked secret data into web UI error messages and logs. This issue affects Argo CD 1.8 versions prior...Show more |
An Information Disclosure vulnerability exists in dhcms 2017-09-18 when entering invalid characters after the normal interface, which causes an error that will leak the physical path. |
1Mendix 1Database Replication Jun 17, 2026 May 12, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Uploading a table mapping using a manipulated XML file results in an exception that could expose information about the application-server and the used XML-framework on the Mendix Database Replication Module (All versions...Show more |
A vulnerability has been identified in Mendix Excel Importer Module (All versions < V9.0.3). Uploading a manipulated XML File results in an exception that could expose information about the Application-Server and the use...Show more |
IBM OpenPages GRC Platform 8.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against t...Show more |
1Node Etsy Client Project 1Node Etsy Client Jun 17, 2026 Apr 1, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 node-etsy-client is a NodeJs Etsy ReST API Client. Applications that are using node-etsy-client and reporting client error to the end user will offer api key value too This is fixed in node-etsy-client v0.3.0 and later. |
1Django Registration Project 1Django Registration Jun 17, 2026 Apr 1, 2021 N/A· v4 2.6 LOW· v3 3.5 LOW· v2 django-registration is a user registration package for Django. The django-registration package provides tools for implementing user-account registration flows in the Django web framework. In django-registration prior to...Show more |
2Postgresql Redhat3Enterprise Linux PostgresqlSoftware CollectionsJun 17, 2026 Apr 1, 2021 N/A· v4 4.3 MEDIUM· v3 3.5 LOW· v2 An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under so...Show more |
4Netapp OracleQuarkus+1 more4Communications Cloud Native Core Console Oncommand InsightQuarkus+1 moreJun 17, 2026 Mar 26, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A flaw was found in RESTEasy in all versions of RESTEasy up to 4.6.0.Final. The endpoint class and method names are returned as part of the exception response when RESTEasy cannot convert one of the request URI path or q...Show more |
An issue was identified in GitLab EE 13.4 or later which leaked internal IP address via error messages. |
An issue has been discovered in GitLab affecting all versions starting with 7.1. A member of a private group was able to validate the use of a specific name for private project. |
1Microfocus 1Solutions Business Manager Jun 17, 2026 Feb 26, 2021 N/A· v4 3.5 LOW· v3 2.7 LOW· v2 Micro Focus Solutions Business Manager Application Repository versions prior to 11.7.1 are vulnerable to information disclosure. |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreJun 17, 2026 Feb 26, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed information about the resource. This vulnerability affects Firefox...Show more |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreJun 17, 2026 Feb 26, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive...Show more |
1Redhat 4Jboss Fuse KeycloakOpenshift Application Runtimes+1 moreJun 17, 2026 Feb 11, 2021 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack. |
1Ibm 1Security Verify Information Queue Jun 17, 2026 Feb 11, 2021 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in fu...Show more |
IBM Cloud Pak for Security (CP4S) 1.3.0.1 and 1.4.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in fu...Show more |
1Ibm 1Security Guardium Insights Jun 17, 2026 Jan 13, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Security Guardium Insights 2.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks aga...Show more |
1Ibm 1Security Guardium Insights Jun 17, 2026 Jan 13, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 IBM Security Guardium Insights 2.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks aga...Show more |
Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, when a download error is triggered in the user portal, an SQL query is displayed to the user. This is fixed in versions 2.7...Show more |