CWE-209
607 CVEs • Abstraction: Base • Likelihood of Exploit: High
Generation of Error Message Containing Sensitive Information
The product generates an error message that includes sensitive information about its environment, users, or associated data.
CVEs (607)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure. |
1Auth0 1Auth0 Wcf Service Jwt Jun 17, 2026 Apr 11, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Auth0 Auth0-WCF-Service-JWT before 1.0.4 leaks the expected JWT signature in an error message when it cannot successfully validate the JWT signature. If this error message is presented to an attacker, they can forge an a...Show more |
2Elastic Netapp2Active Iq Performance Analytics Services LogstashJun 17, 2026 Mar 25, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A sensitive data disclosure flaw was found in the way Logstash versions before 5.6.15 and 6.6.1 logs malformed URLs. If a malformed URL is specified as part of the Logstash configuration, the credentials for the URL coul...Show more |
1Dropbear Ssh Project 1Dropbear Ssh Nov 21, 2024 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the max...Show more |
In JForum 2.1.8, an unauthenticated, remote attacker can enumerate whether a user exists by using the "create user" function. If a register/check/username?username= request corresponds to a username that exists, then an...Show more |
A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal IDs. This is issue is...Show more |
4Artifex CanonicalDebian+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 21, 2024 Oct 15, 2018 N/A· v4 8.6 HIGH· v3 6.8 MEDIUM· v2 Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incomplete fix for CVE-2018-17183. |
Carestream Vue RIS, RIS Client Builds: Version 11.2 and prior running on a Windows 8.1 machine with IIS/7.5. When contacting a Carestream server where there is no Oracle TNS listener available, users will trigger an HTTP...Show more |
4Debian GlusterOpensuse+1 more5Debian Linux Enterprise Linux ServerGlusterfs+2 moreNov 21, 2024 Sep 4, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An information disclosure vulnerability was discovered in glusterfs server. An attacker could issue a xattr request via glusterfs FUSE to determine the existence of any file. |
Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace revealing use of net.sf.acegisecurity components. |
The Web server in 3CX version 15.5.8801.3 is vulnerable to Information Leakage, because of improper error handling in Stack traces, as demonstrated by discovering a full pathname. |
1Johnsoncontrols 2Bcpro Metasys SystemNov 21, 2024 Aug 1, 2018 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could all...Show more |
Apache Ambari, version 2.5.0 to 2.6.2, passwords for Hadoop credential stores are exposed in Ambari Agent informational log messages when the credential store feature is enabled for eligible services. For example, Hive a...Show more |
2Eclipse Oracle2Jetty Retail Xstore Point Of ServiceNov 21, 2024 Jun 27, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServl...Show more |
2Ovirt Redhat3Ovirt Engine VirtualizationVirtualization HostNov 21, 2024 Jun 19, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The web console login form in ovirt-engine before version 4.2.3 returned different errors for non-existent users and invalid passwords, allowing an attacker to discover the names of valid user accounts. |
An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error or navigating to a previous install step, and display the plaintext pa...Show more |
hawtio before versions 2.0-beta-1, 2.0-beta-2 2.0-m1, 2.0-m2, 2.0-m3, and 1.5 is vulnerable to a path traversal that leads to a NullPointerException with a full stacktrace. An attacker could use this flaw to gather undis...Show more |
1Sap 1Hana Extended Application Services Nov 21, 2024 Feb 14, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given username is valid by evaluating error messages of a specific endpoint. |
1Fedoraproject 1389 Directory Server May 13, 2026 Aug 16, 2017 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts. |
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user credentials, through an error message from the Report Builder administrator configuration page. IBM X-Force ID: 126863. |